Arbitrary File Upload Vulnerability in Kiteworks by Kiteworks
CVE-2026-28270
4.9MEDIUM
What is CVE-2026-28270?
Kiteworks, a private data network solution, contains a vulnerability that allows for the uploading of arbitrary files without adequate validation in versions prior to 9.2.0. This flaw could be exploited by malicious administrators to upload unauthorized file types, potentially leading to unauthorized access or data breaches. The issue has been addressed in version 9.2.0, which includes a patch to enhance the security of the system.
Affected Version(s)
security-advisories < 9.2.0
