CVE-2026-24750

7.6

Kiteworks · Secure Data Forms

Kiteworks Secure Data Forms contains a stored cross-site scripting vulnerability in versions prior to 9.2.1, allowing authenticated attackers to execute malicious scripts when modifying forms.

Executive summary

An authenticated stored cross-site scripting vulnerability in Kiteworks Secure Data Forms exposes organizations to potential session hijacking and malicious script execution.

Vulnerability

The vulnerability is a stored cross-site scripting (XSS) issue caused by improper neutralization of input during web page generation. An authenticated attacker can inject malicious payloads into forms, which are then executed in the context of other users who view or interact with the modified forms.

Business impact

This vulnerability carries a CVSS score of 7.6, indicating a high severity due to the potential for unauthorized access and data manipulation. Successful exploitation allows an attacker to compromise user sessions or perform actions on behalf of other users, which could lead to significant data exposure or unauthorized modification of sensitive information within the private data network.

Remediation

Immediate Action: Upgrade the Kiteworks Secure Data Forms component to version 9.2.1 or later to apply the necessary security patch.

Proactive Monitoring: Review web application access logs for unusual patterns or suspicious script injections within form submission fields.

Compensating Controls: Implement or tune a Web Application Firewall (WAF) to detect and block common XSS payloads, providing a temporary layer of defense until the software update is applied.

Exploitation status

Public Exploit Available: No — exploit_available is false.

Analyst recommendation

Given the high CVSS score and the nature of stored XSS, organizations should prioritize updating their Kiteworks environment to version 9.2.1 immediately. Relying on compensating controls alone is insufficient, as these may be bypassed by sophisticated payload obfuscation. Ensure that all administrative and user-facing forms are reviewed for anomalous content during the transition to the patched version.

More Kiteworks CVEs

Sources