CVE-2026-23514
Awaiting Analysis Awaiting Analysis - Queue
Access Control Vulnerability in Kiteworks Core Allows Unauthorized Access

Publication date: 2026-03-25

Last updated on: 2026-03-27

Assigner: GitHub, Inc.

Description
Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized content. Upgrade Kiteworks Core to version 9.2.2 or later to receive a patch.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-03-25
Last Modified
2026-03-27
Generated
2026-05-07
AI Q&A
2026-03-25
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
accellion kiteworks 9.2.0
accellion kiteworks 9.2.1
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-282 The product assigns the wrong ownership, or does not properly verify the ownership, of an object or resource.
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :

The vulnerability can lead to unauthorized access to sensitive or restricted content by users who should not have permission, potentially compromising confidentiality, integrity, and availability of data.

Given the CVSS score of 8.8, the impact is considered high, affecting confidentiality, integrity, and availability.


Can you explain this vulnerability to me?

This vulnerability exists in Kiteworks Core versions 9.2.0 and 9.2.1, where an access control flaw allows authenticated users to access content they are not authorized to view.

The issue is resolved by upgrading to Kiteworks Core version 9.2.2 or later.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, upgrade Kiteworks Core to version 9.2.2 or later, as these versions include the patch that fixes the access control issue.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

CVE-2026-23514 allows authenticated users with low privileges to access unauthorized content, leading to high confidentiality, integrity, and availability losses. Such unauthorized access and potential data modification or disruption can negatively impact compliance with data protection standards and regulations like GDPR and HIPAA, which require strict access controls and protection of sensitive data.

Failure to prevent unauthorized access to sensitive data may result in violations of these regulations, potentially leading to legal and financial consequences.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart