Kiteworks is a private data network (PDN). Prior to version 9.2.1, a vulnerability in Kiteworks Email Protection Gateway session management allows blocked users to maintain active sessions after their account is disabled. This could allow unauthorized access to continue until the session naturally expires. Upgrade Kiteworks to version 9.2.1 or later to receive a patch.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kiteworks
Kiteworks kiteworks Email Protection Gateway |
|
| Vendors & Products |
Kiteworks
Kiteworks kiteworks Email Protection Gateway |
Wed, 25 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kiteworks is a private data network (PDN). Prior to version 9.2.1, a vulnerability in Kiteworks Email Protection Gateway session management allows blocked users to maintain active sessions after their account is disabled. This could allow unauthorized access to continue until the session naturally expires. Upgrade Kiteworks to version 9.2.1 or later to receive a patch. | |
| Title | Kiteworks Email Protection Gateway has an Insufficient Session Expiration | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-25T17:29:41.481Z
Reserved: 2026-03-03T21:54:06.707Z
Link: CVE-2026-29092
Updated: 2026-03-25T17:29:36.886Z
Status : Awaiting Analysis
Published: 2026-03-25T17:16:57.330
Modified: 2026-03-26T15:13:15.790
Link: CVE-2026-29092
No data.
OpenCVE Enrichment
Updated: 2026-03-26T11:34:24Z