Vulnerability Details CVE-2026-23635
Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, a misconfiguration of the security attributes could potentially lead to Unprotected Transport of Credentials under certain circumstances. Upgrade Kiteworks to version 9.2.1 or later to receive a patch.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 8.6%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-23635
-
cpe:2.3:a:accellion:kiteworks:7.3.0
-
cpe:2.3:a:accellion:kiteworks:7.3.1
-
cpe:2.3:a:accellion:kiteworks:7.3.2
-
cpe:2.3:a:accellion:kiteworks:7.4.0
-
cpe:2.3:a:accellion:kiteworks:9.1.0