CVE-2026-28272 | kiteworks up to 9.1.x User Interface cross site scripting (GHSA-7hxj-ch78-xqgr / EUVD-2026-9067)
A vulnerability classified as problematic was found in kiteworks up to 9.1.x. The affected element is an unknown function of the component User Interface. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-28272. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.