Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized content. Upgrade Kiteworks Core to version 9.2.2 or later to receive a patch.
References
| Link | Resource |
|---|---|
| https://github.com/kiteworks/security-advisories/security/advisories/GHSA-5gqr-cpr6-wvm5 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
27 Mar 2026, 18:52
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CPE | cpe:2.3:a:accellion:kiteworks:9.2.0:*:*:*:*:*:*:* cpe:2.3:a:accellion:kiteworks:9.2.1:*:*:*:*:*:*:* |
|
| References | () https://github.com/kiteworks/security-advisories/security/advisories/GHSA-5gqr-cpr6-wvm5 - Vendor Advisory | |
| First Time |
Accellion kiteworks
Accellion |
25 Mar 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-25 15:16
Updated : 2026-03-27 18:52
NVD link : CVE-2026-23514
Mitre link : CVE-2026-23514
CVE.ORG link : CVE-2026-23514
JSON object : View
Products Affected
accellion
- kiteworks
CWE
CWE-282
Improper Ownership Management
