# CVE-2026-23514

## Summary

- **CVE ID:** CVE-2026-23514
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-282
- **Published:** Mar 25, 2026
- **Last Modified:** Mar 25, 2026

## Description

Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized content. Upgrade Kiteworks Core to version 9.2.2 or later to receive a patch.

## Affected Products

- kiteworks — core (>= 9.2.0, < 9.2.2)

## References

- [CNA](https://github.com/kiteworks/security-advisories/security/advisories/GHSA-5gqr-cpr6-wvm5)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.04%
- **EPSS Percentile:** 62.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._