CVE-2026-28269 is a high-severity vulnerability affecting Kiteworks private data network (PDN) versions prior to 9.2.0. It allows authenticated users to redirect command output to arbitrary file locations, potentially overwriting critical system files and leading to elevated access. With a CVSS score of 8.8 (HIGH), this vulnerability has a low attack complexity and can result in high impacts to confidentiality, integrity, and availability. There is currently no public exploit intelligence, Metasploit modules, or Nuclei templates available, and it has not been added to CISA's KEV catalog. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.2.0CPE matchmatch criteria | cpe:2.3:a:accellion:kiteworks:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.