CVE-2026-23514
8.8Kiteworks · Kiteworks Core
Kiteworks Core versions 9.2.0 and 9.2.1 contain an access control vulnerability that enables authenticated users to gain unauthorized access to restricted content.
Executive summary
An access control vulnerability in Kiteworks Core allows authenticated users to bypass security restrictions and access sensitive data.
Vulnerability
This flaw involves improper ownership management, categorized as CWE-282, which permits an authenticated user to access unauthorized content due to insufficient access controls.
Business impact
The ability for authenticated users to access restricted data poses a significant risk to organizational confidentiality and data integrity. Given the CVSS score of 8.8, this vulnerability is classified as High, reflecting the potential for severe unauthorized data exposure and the compromise of private information networks.
Remediation
Immediate Action: Upgrade Kiteworks Core to version 9.2.2 or later to apply the necessary security patch.
Proactive Monitoring: Review system access logs for anomalous patterns, specifically looking for users attempting to access directories or files outside their assigned scope of authority.
Compensating Controls: While no direct virtual patch is specified, ensure that robust identity and access management (IAM) policies are strictly enforced to limit the potential reach of compromised user accounts.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability presents a high risk to data privacy within the Kiteworks platform. Administrators must prioritize the upgrade to version 9.2.2 immediately to neutralize the access control deficiency and prevent potential data exfiltration by unauthorized internal or compromised accounts.