CVE-2024-28064: Kiteworks Totemomail

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Kiteworks Totemomail 7.x and 8.x before 8.3.0 allows /responsiveUI/EnvelopeOpenServlet messageId directory traversal for unauthenticated file read and delete operations (with displayLoginChunkedImages) and write operations (with storeLoginChunkedImages).

Affected products

  • Kiteworks Totemomail: from 7.0, before 8.0 (fixed in 8.0); from 8.0, before 8.3.0 (fixed in 8.3.0)

Published 2024-05-18. Last modified 2026-06-17.