Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized content. Upgrade Kiteworks Core to version 9.2.2 or later to receive a patch.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Accellion
Accellion kiteworks |
|
| CPEs | cpe:2.3:a:accellion:kiteworks:9.2.0:*:*:*:*:*:*:* cpe:2.3:a:accellion:kiteworks:9.2.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Accellion
Accellion kiteworks |
Thu, 26 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kiteworks
Kiteworks core |
|
| Vendors & Products |
Kiteworks
Kiteworks core |
Wed, 25 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Mar 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized content. Upgrade Kiteworks Core to version 9.2.2 or later to receive a patch. | |
| Title | Kiteworks Core before 9.2.2 is vulnerable to Improper Ownership Management | |
| Weaknesses | CWE-282 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-25T14:19:01.421Z
Updated: 2026-03-25T14:45:43.015Z
Reserved: 2026-01-13T18:22:43.979Z
Link: CVE-2026-23514
Updated: 2026-03-25T14:45:31.918Z
Status : Analyzed
Published: 2026-03-25T15:16:37.967
Modified: 2026-03-27T18:52:37.110
Link: CVE-2026-23514
No data.