Kiteworks Core Access Control Vulnerability Allowing Unauthorized Content Access

Vulnerability

An access control vulnerability has been identified in Kiteworks Core versions 9.2.0 and 9.2.1. This vulnerability allows authenticated users to access content they are not authorized to view. The issue arises from improper ownership management, creating a loophole in the access control mechanism.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive content by authenticated users.

Remediation

Users are advised to upgrade Kiteworks Core to version 9.2.2 or later.

Added: Mar 25, 2026, 3:22 PM
Updated: Mar 25, 2026, 3:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
0.0
relevance
4.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.