CVE-2026-23514
Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized content. Upgrade Kiteworks Core to version 9.2.2 or later to receive a patch.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 1.04%
- CWE
- CWE-282
- Published
- 2026-03-25
- Last modified
- 2026-03-25
Affected products
- kiteworks core
Weakness type
Related vulnerabilities
- CVE-2026-86769 — Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout
- CVE-2026-50130 — Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`
- CVE-2026-40214 — In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project...
- CVE-2026-3867 — An improper ownership management vulnerability has been identified in Moxa’s Secure Router. Because...
- CVE-2025-57732 — In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory...
- CVE-2025-1112 — IBM OpenPages with Watson information disclosure
- CVE-2025-46416 — The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can...
- CVE-2025-3629 — IBM InfoSphere Information Server file manipulation