CVE-2026-29092: Kiteworks Email Protection Gateway has an Insufficient Session Expiration
Kiteworks is a private data network (PDN). Prior to version 9.2.1, a vulnerability in Kiteworks Email Protection Gateway session management allows blocked users to maintain active sessions after their account is disabled. This could allow unauthorized access to continue until the session naturally expires. Upgrade Kiteworks to version 9.2.1 or later to receive a patch.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29092?
CVE-2026-29092 is classified as a high severity vulnerability due to insufficient session expiration in Kiteworks Email Protection Gateway.
How do I fix CVE-2026-29092?
To fix CVE-2026-29092, upgrade Kiteworks Email Protection Gateway to version 9.2.1 or later to ensure proper session management.
Does CVE-2026-29092 affect all versions of Kiteworks Email Protection Gateway?
CVE-2026-29092 affects all versions of Kiteworks Email Protection Gateway prior to version 9.2.1.
What impact does CVE-2026-29092 have on users?
CVE-2026-29092 allows blocked users to maintain active sessions, potentially exposing sensitive data and posing security risks.
Can I mitigate CVE-2026-29092 without upgrading?
Mitigation for CVE-2026-29092 without upgrading is limited, and the best course of action is to apply the latest patch.