Kiteworks Email Protection Gateway Insufficient Session Expiration Vulnerability
Vulnerability
A session management vulnerability has been identified in Kiteworks Email Protection Gateway versions prior to 9.2.1. This vulnerability allows users with blocked accounts to retain active sessions even after their accounts have been disabled. As a result, these users could potentially access the system without authorization until their sessions naturally expire.
Impact
Exploitation of this vulnerability could lead to unauthorized access by allowing blocked users to maintain active sessions after their accounts have been disabled.
Remediation
Users are advised to upgrade Kiteworks to version 9.2.1 or later.
Added: Mar 25, 2026, 7:18 PM
Updated: Mar 25, 2026, 7:18 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
1.3exploitability
4.8remediation
0.0relevance
4.7threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
