Tag
high
advisory
Kiteworks Core Access Control Vulnerability (CVE-2026-23514)
2 rules 1 TTPKiteworks Core versions 9.2.0 and 9.2.1 contain an access control vulnerability (CVE-2026-23514) due to improper ownership management, allowing authenticated users to access unauthorized content, which can be mitigated by upgrading to version 9.2.2 or later.
access-control
vulnerability
kiteworks
2r
1t
medium
advisory
Kiteworks Secure Data Forms Stored XSS Vulnerability (CVE-2026-24750)
2 rules 1 TTP 1 IOCAn authenticated attacker can exploit a stored XSS vulnerability (CVE-2026-24750) in Kiteworks Secure Data Forms before version 9.2.1 due to improper neutralization of input, leading to arbitrary script execution in the context of other users.
Kiteworks Secure Data Forms
xss
web-application
kiteworks
2r
1t
1i