CVE-2026-28272
8.1Kiteworks · Email Protection Gateway
A stored cross-site scripting (XSS) vulnerability in the Kiteworks Email Protection Gateway allows authenticated administrators to inject malicious scripts via the configuration interface.
Executive summary
A stored cross-site scripting vulnerability in the Kiteworks Email Protection Gateway could allow an authenticated administrator to execute malicious scripts within the interface of other users.
Vulnerability
This is a stored cross-site scripting (CWE-79) flaw residing in the configuration interface. An authenticated administrator can inject malicious scripts that execute when unsuspecting users interact with the compromised interface.
Business impact
The vulnerability carries a CVSS score of 8.1, which reflects a high severity due to the potential for privilege escalation and unauthorized actions performed on behalf of legitimate users. Successful exploitation could lead to session hijacking, sensitive data exposure, or unauthorized configuration changes, potentially compromising the integrity of the organization's private data network.
Remediation
Immediate Action: Upgrade the Kiteworks Email Protection Gateway to version 9.2.0 or later to apply the necessary security patch.
Proactive Monitoring: Review administrative access logs for unusual configuration changes and monitor web traffic for evidence of injected script payloads.
Compensating Controls: Implement a Web Application Firewall (WAF) with strict XSS filtering rules to inspect administrative traffic and block malicious script injection attempts.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for unauthorized script execution within the administration environment, organizations should prioritize the update to version 9.2.0. Administrators should audit the configuration interface for any suspicious entries and enforce strict access control policies to minimize the risk of malicious activity by privileged accounts.