github.comConfirmation
https://github.com/kiteworks/security-advisories/security/advisories/GHSA-5gqr-cpr6-wvm5 CVE-2026-23514
HIGH
Kiteworks Core before 9.2.2 is vulnerable to Improper Ownership Management
Record summary
CVE-2026-23514 has a selected CVSS score of 8.8 (high).
Description
Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized content. Upgrade Kiteworks Core to version 9.2.2 or later to receive a patch.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 25, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | >= 9.2.0, < 9.2.2 | affected |