CVE-2026-23514

8.8

Kiteworks · Kiteworks Core

Kiteworks Core versions 9.2.0 and 9.2.1 contain an access control vulnerability that enables authenticated users to gain unauthorized access to restricted content.

Executive summary

An access control vulnerability in Kiteworks Core allows authenticated users to bypass security restrictions and access sensitive data.

Vulnerability

This flaw involves improper ownership management, categorized as CWE-282, which permits an authenticated user to access unauthorized content due to insufficient access controls.

Business impact

The ability for authenticated users to access restricted data poses a significant risk to organizational confidentiality and data integrity. Given the CVSS score of 8.8, this vulnerability is classified as High, reflecting the potential for severe unauthorized data exposure and the compromise of private information networks.

Remediation

Immediate Action: Upgrade Kiteworks Core to version 9.2.2 or later to apply the necessary security patch.

Proactive Monitoring: Review system access logs for anomalous patterns, specifically looking for users attempting to access directories or files outside their assigned scope of authority.

Compensating Controls: While no direct virtual patch is specified, ensure that robust identity and access management (IAM) policies are strictly enforced to limit the potential reach of compromised user accounts.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability presents a high risk to data privacy within the Kiteworks platform. Administrators must prioritize the upgrade to version 9.2.2 immediately to neutralize the access control deficiency and prevent potential data exfiltration by unauthorized internal or compromised accounts.

More Kiteworks CVEs

Sources