📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global supply_chain Software Development and Technology CRITICAL 1h Global data_breach Multiple Sectors HIGH 1h Global vulnerability Consumer Electronics / Mobile Devices CRITICAL 2h Global phishing Cybersecurity / Network Security CRITICAL 2h Global malware Critical Infrastructure / Government HIGH 3h Global supply_chain Cybersecurity / Software Supply Chain CRITICAL 3h Global general Multiple sectors MEDIUM 5h Global general Multiple sectors MEDIUM 5h Global malware Information Technology and Telecommunications HIGH 5h Global phishing,ransomware,general Multiple sectors across Asia-Pacific region HIGH 6h Global supply_chain Software Development and Technology CRITICAL 1h Global data_breach Multiple Sectors HIGH 1h Global vulnerability Consumer Electronics / Mobile Devices CRITICAL 2h Global phishing Cybersecurity / Network Security CRITICAL 2h Global malware Critical Infrastructure / Government HIGH 3h Global supply_chain Cybersecurity / Software Supply Chain CRITICAL 3h Global general Multiple sectors MEDIUM 5h Global general Multiple sectors MEDIUM 5h Global malware Information Technology and Telecommunications HIGH 5h Global phishing,ransomware,general Multiple sectors across Asia-Pacific region HIGH 6h Global supply_chain Software Development and Technology CRITICAL 1h Global data_breach Multiple Sectors HIGH 1h Global vulnerability Consumer Electronics / Mobile Devices CRITICAL 2h Global phishing Cybersecurity / Network Security CRITICAL 2h Global malware Critical Infrastructure / Government HIGH 3h Global supply_chain Cybersecurity / Software Supply Chain CRITICAL 3h Global general Multiple sectors MEDIUM 5h Global general Multiple sectors MEDIUM 5h Global malware Information Technology and Telecommunications HIGH 5h Global phishing,ransomware,general Multiple sectors across Asia-Pacific region HIGH 6h
Vulnerabilities

CVE-2026-24750

High
Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, an authenticated attacker could exploit an Improper Neutralization of Input During Web Page Generation
CWE-79 — Weakness Type
Published: Mar 25, 2026  ·  Modified: Mar 28, 2026  ·  Source: NVD
CVSS v3
7.6
🔗 NVD Official
📄 Description (English)

Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, an authenticated attacker could exploit an Improper Neutralization of Input During Web Page Generation as Stored XSS when modifying forms. Upgrade Kiteworks to version 9.2.1 or later to receive a patch.

🤖 AI Executive Summary

CVE-2026-24750 is a stored XSS vulnerability in Kiteworks Secure Data Forms affecting versions prior to 9.2.1, exploitable by authenticated users during form modification. With a CVSS score of 7.6, this vulnerability poses a significant risk to organizations using Kiteworks for secure data exchange, particularly those handling sensitive government and financial data. No public exploit is currently available, but the vulnerability requires immediate patching upon release. Organizations should prioritize upgrading to version 9.2.1 or later to mitigate potential data compromise and unauthorized access.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 29, 2026 22:52
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses significant risk to Saudi banking sector (SAMA-regulated institutions), government agencies (NCA oversight), and healthcare organizations using Kiteworks for secure data exchange. Saudi Aramco and energy sector entities relying on Kiteworks for confidential communications are particularly vulnerable. Telecom operators (STC, Mobily) and financial institutions handling cross-border transactions face elevated risk of data exfiltration and compliance violations. The stored XSS nature allows persistent compromise of form data, potentially affecting multiple users and enabling lateral movement within organizational networks.
🏢 Affected Saudi Sectors
Banking and Financial Services Government and Public Administration Healthcare and Medical Services Energy and Utilities Telecommunications Defense and Security Legal and Professional Services
⚖️ Saudi Risk Score (AI)
7.8
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all Kiteworks instances in your environment and document current versions
2. Restrict form modification capabilities to essential personnel only
3. Implement input validation and output encoding at application layer
4. Enable Web Application Firewall (WAF) rules to detect XSS patterns in form submissions
5. Monitor Kiteworks audit logs for suspicious form modifications

PATCHING GUIDANCE:
1. Upgrade to Kiteworks version 9.2.1 or later immediately upon availability
2. Test patches in non-production environment before deployment
3. Schedule maintenance windows for production upgrades
4. Verify patch installation and validate form functionality post-upgrade

COMPENSATING CONTROLS (if patch unavailable):
1. Implement network segmentation to limit Kiteworks access
2. Deploy endpoint detection and response (EDR) solutions
3. Enable multi-factor authentication (MFA) for all Kiteworks users
4. Conduct regular security awareness training on XSS risks
5. Implement Content Security Policy (CSP) headers

DETECTION RULES:
1. Monitor for script tags (<script>) in form field submissions
2. Alert on unusual form modification patterns by non-administrative users
3. Track changes to form templates and stored procedures
4. Monitor for encoded XSS payloads (e.g., &#x3c;script&#x3e;)
5. Implement SIEM rules for suspicious JavaScript execution in web contexts
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. حدد جميع مثيلات Kiteworks في بيئتك وقثق الإصدارات الحالية
2. قيد قدرات تعديل النماذج للموظفين الأساسيين فقط
3. طبق التحقق من الإدخال والترميز الناتج على مستوى التطبيق
4. فعّل قواعد جدار حماية تطبيقات الويب (WAF) للكشف عن أنماط XSS في تقديمات النماذج
5. راقب سجلات تدقيق Kiteworks للتعديلات المريبة على النماذج

إرشادات التصحيح:
1. قم بالترقية إلى إصدار Kiteworks 9.2.1 أو أحدث فوراً عند توفره
2. اختبر التصحيحات في بيئة غير الإنتاج قبل النشر
3. جدول نوافذ الصيانة لترقيات الإنتاج
4. تحقق من تثبيت التصحيح والتحقق من وظائف النموذج بعد الترقية

الضوابط البديلة (إذا لم يكن التصحيح متاحاً):
1. طبق تقسيم الشبكة لتحديد وصول Kiteworks
2. نشر حلول الكشف والاستجابة على نقطة النهاية (EDR)
3. فعّل المصادقة متعددة العوامل (MFA) لجميع مستخدمي Kiteworks
4. أجرِ تدريباً منتظماً على الوعي الأمني بشأن مخاطر XSS
5. طبق رؤوس سياسة أمان المحتوى (CSP)

قواعد الكشف:
1. راقب علامات البرنامج النصي (<script>) في تقديمات حقول النموذج
2. نبّه على أنماط تعديل النموذج غير العادية من قبل المستخدمين غير الإداريين
3. تتبع التغييرات على قوالب النموذج والإجراءات المخزنة
4. راقب حمولات XSS المشفرة (مثل &#x3c;script&#x3e;)
5. طبق قواعد SIEM لتنفيذ JavaScript المريب في السياقات الويب
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.14.2.1 - Information security requirements for supplier relationships ECC 2024 A.14.2.5 - Addressing information security in supplier agreements ECC 2024 A.5.23 - Web application security controls ECC 2024 A.6.14 - Secure development and change management
🔵 SAMA CSF
SAMA CSF ID.BE-3 - Third-party risk management SAMA CSF PR.DS-1 - Data security and protection SAMA CSF PR.AC-1 - Access control and authentication SAMA CSF DE.CM-1 - Detection and monitoring
🟡 ISO 27001:2022
ISO 27001:2022 A.5.23 - Web application security ISO 27001:2022 A.6.5 - Access control ISO 27001:2022 A.8.24 - Secure development and change management ISO 27001:2022 A.12.6.1 - Management of technical vulnerabilities
🟣 PCI DSS v4.0.1
PCI DSS 6.5.1 - Injection flaws prevention PCI DSS 6.5.7 - Cross-site scripting (XSS) prevention PCI DSS 11.3 - Penetration testing and vulnerability scanning
📦 Affected Products / CPE 1 entries
accellion:kiteworks
📊 CVSS Score
7.6
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionR — Required
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityL — Low / Local
📋 Quick Facts
Severity High
CVSS Score7.6
CWECWE-79
Exploit No
Patch ✗ No
Published 2026-03-25
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
7.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-79
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.