Arbitrary File Upload Vulnerability in Kiteworks by Kiteworks
CVE-2026-28270

4.9MEDIUM

Key Information:

Vendor

Kiteworks

Vendor
CVE Published:
27 February 2026

What is CVE-2026-28270?

Kiteworks, a private data network solution, contains a vulnerability that allows for the uploading of arbitrary files without adequate validation in versions prior to 9.2.0. This flaw could be exploited by malicious administrators to upload unauthorized file types, potentially leading to unauthorized access or data breaches. The issue has been addressed in version 9.2.0, which includes a patch to enhance the security of the system.

Affected Version(s)

security-advisories < 9.2.0

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.