Vulnerability Details CVE-2026-24754
Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS vulnerability in Kiteworks Secure Data Forms could allow an authenticated attacker to execute arbitrary JavaScript code in other users' sessions. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 8.6%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2026-24754
-
cpe:2.3:a:accellion:kiteworks:7.3.0
-
cpe:2.3:a:accellion:kiteworks:7.3.1
-
cpe:2.3:a:accellion:kiteworks:7.3.2
-
cpe:2.3:a:accellion:kiteworks:7.4.0
-
cpe:2.3:a:accellion:kiteworks:9.1.0