CVE-2026-29092: Kiteworks Email Protection Gateway has an Insufficient Session Expiration

Published Mar 25, 2026
·
Updated

Kiteworks is a private data network (PDN). Prior to version 9.2.1, a vulnerability in Kiteworks Email Protection Gateway session management allows blocked users to maintain active sessions after their account is disabled. This could allow unauthorized access to continue until the session naturally expires. Upgrade Kiteworks to version 9.2.1 or later to receive a patch.

Affected Software

2 affected components
Kiteworks Email Protection Gateway<9.2.1
Accellion Kiteworks<9.2.1

Event History

Mar 25, 2026
CVE Published
via MITRE·04:59 PM
Data Sourced
via MITRE·04:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-29092?

CVE-2026-29092 is classified as a high severity vulnerability due to insufficient session expiration in Kiteworks Email Protection Gateway.

2

How do I fix CVE-2026-29092?

To fix CVE-2026-29092, upgrade Kiteworks Email Protection Gateway to version 9.2.1 or later to ensure proper session management.

3

Does CVE-2026-29092 affect all versions of Kiteworks Email Protection Gateway?

CVE-2026-29092 affects all versions of Kiteworks Email Protection Gateway prior to version 9.2.1.

4

What impact does CVE-2026-29092 have on users?

CVE-2026-29092 allows blocked users to maintain active sessions, potentially exposing sensitive data and posing security risks.

5

Can I mitigate CVE-2026-29092 without upgrading?

Mitigation for CVE-2026-29092 without upgrading is limited, and the best course of action is to apply the latest patch.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203