Home

Description

Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized content. Upgrade Kiteworks Core to version 9.2.2 or later to receive a patch.

PUBLISHED Reserved 2026-01-13 | Published 2026-03-25 | Updated 2026-03-25 | Assigner GitHub_M




HIGH: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-282: Improper Ownership Management

Product status

>= 9.2.0, < 9.2.2
affected

References

github.com/...sories/security/advisories/GHSA-5gqr-cpr6-wvm5

cve.org (CVE-2026-23514)

nvd.nist.gov (CVE-2026-23514)

Download JSON