CVE-2026-28271: Accellion Kiteworks
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functionality allows bypassing of SSRF protections through DNS rebinding attacks. Malicious administrators could exploit this to access internal services that should be restricted. Version 9.2.0 contains a patch for the issue.
Affected products
- Accellion Kiteworks: before 9.2.0 (fixed in 9.2.0)
Published 2026-02-27. Last modified 2026-06-17.