← Vulnerability feed

Vulnerability record · CVE-2026-23636 · published 25 March 2026

CVE-2026-23636: Accellion kiteworks unrestricted file upload vulnerability

Accellion · Kiteworks

Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, the manager of a form could potentially exploit an Unrestricted Upload of File with Dangerous Type due to a missing validation. Upgrade Kiteworks to version 9.2.1 or later to receive a patch.

7.2 CVSS 3.1 High EPSS 0.99% · top 39.0% CWE-434 · Unrestricted file upload
7.2CVSS 3.1 base score
0.99%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, the manager of a form could potentially exploit an Unrestricted Upload of File with Dangerous Type due to a missing validation. Upgrade Kiteworks to version 9.2.1 or later to receive a patch.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-23636 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-24782Accellion kiteworks sql injection vulnerabilityKiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL Injection vulnerabilities in Kiteworks Secure Data Forms could be explo…EPSS 0.67%8.8CVE-2026-28269Accellion kiteworks os command injection vulnerabilityKiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functionality allows authenticated u…EPSS 3.0%8.8CVE-2025-53939Accellion kiteworks improper input validation vulnerabilityKiteworks is a private data network (PDN). Prior to version 9.1.0, improper input validation when managing roles of a shared folder could lead to une…EPSS 0.74%8.8CVE-2021-31586Accellion kiteworks sql injection vulnerabilityAccellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search.EPSS 44%8.2CVE-2026-24752Accellion kiteworks cross-site scripting vulnerabilityKiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an extern…EPSS 0.28%8.2CVE-2026-24751Accellion kiteworks cross-site scripting vulnerabilityKiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an extern…EPSS 0.29%7.5CVE-2026-29092Accellion kiteworks insufficient session expiration vulnerabilityKiteworks is a private data network (PDN). Prior to version 9.2.1, a vulnerability in Kiteworks Email Protection Gateway session management allows bl…EPSS 0.34%7.2CVE-2026-28270Accellion kiteworks unrestricted file upload vulnerabilityKiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows uploading of arbitrary files wit…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2026-23636), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.