


Perceptive Security
SOC/SIEM Consultancy

Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker…
Published:
31 May 2026 at 22:00:00
Alert date:
1 June 2026 at 22:04:03
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A reflected cross-site scripting (XSS) vulnerability affects Kiteworks Secure Data Forms in versions prior to 9.3.0. The vulnerability allows external attackers to trick users into executing arbitrary JavaScript code. Kiteworks is a private data network (PDN) platform. The issue has been patched in version 9.3.0 and later. Organizations using affected versions should upgrade immediately to mitigate the risk.
Technical details
Mitigation steps:
Affected products:
Kiteworks
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-24751
https://github.com/kiteworks/security-advisories/security/advisories/GHSA-xp8m-wmmp-f947
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
