CVE-2026-23514
Awaiting Analysis
Awaiting Analysis - Queue
Access Control Vulnerability in Kiteworks Core Allows Unauthorized Access
Publication date: 2026-03-25
Last updated on: 2026-03-27
Assigner: GitHub, Inc.
Description
Description
Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized content. Upgrade Kiteworks Core to version 9.2.2 or later to receive a patch.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| accellion | kiteworks | 9.2.0 |
| accellion | kiteworks | 9.2.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-282 | The product assigns the wrong ownership, or does not properly verify the ownership, of an object or resource. |