Kiteworks Email Protection Gateway Insufficient Session Expiration Vulnerability

Vulnerability

A session management vulnerability has been identified in Kiteworks Email Protection Gateway versions prior to 9.2.1. This vulnerability allows users with blocked accounts to retain active sessions even after their accounts have been disabled. As a result, these users could potentially access the system without authorization until their sessions naturally expire.

Impact

Exploitation of this vulnerability could lead to unauthorized access by allowing blocked users to maintain active sessions after their accounts have been disabled.

Remediation

Users are advised to upgrade Kiteworks to version 9.2.1 or later.

Added: Mar 25, 2026, 7:18 PM
Updated: Mar 25, 2026, 7:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
4.8
remediation
0.0
relevance
4.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.