Kiteworks has issued an urgent patch for a critical authentication bypass vulnerability (CVE-2025-47272, CVSS 9.8) affecting versions 7.0.0–8.2.1 of its managed file transfer platform. The flaw allows remote attackers to access sensitive files without credentials by exploiting improper session token validation. Self-hosted users must update to version 8.2.2 immediately.