Loading
Authentication Bypass vulnerability in Accellion kiteworks before 2017.01.00 allows remote attackers to execute certain API calls on behalf of a web user using a gathered token via a POST request to /oauth/token.
Use CWE-287, Accellion vendor hub and Kiteworks product page to widen CVE-2017-9421 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-23514, CVE-2021-31586 and CVE-2026-28272 for nearby disclosures in the same product family.