Junglewise Threat Intelligence

CVE-2026-42051: Kirby CMS information disclosure in system API endpoint

CVE-2026-42051 · Severity: medium · CVSS 4.3 · Published 2026-05-09

Technologies: Kirby CMS, Kirby. Vendors: Kirby.

Executive brief

Kirby is an open-source content management system used to build and manage websites. A security flaw in the system's internal programming interface allows logged-in users to view sensitive license information and the exact version of the software being used, even if they do not have permission to see system settings. This information could be used by a malicious actor to identify specific weaknesses in the site for further attacks.

Technical details

A missing authorization check in the Kirby CMS REST API allows authenticated users to access sensitive system data. Specifically, the `/api/system` endpoint returns the installed Kirby version and license details (status, type, and code) to any authenticated user, bypassing the 'access.system' permission check defined in user blueprints. While this does not allow for direct data modification, it facilitates reconnaissance by providing attackers with version-specific details necessary to plan subsequent exploits. The issue is resolved in versions 4.9.0 and 5.4.0 by implementing a permission check on the version and license properties within the API response.

Affected products

  • Kirby Kirby CMS <= 4.8.0, 5.0.0 to 5.3.3

Timeline

  • 2026-04-23: patched: Versions 4.9.0 and 5.4.0 released
  • 2026-04-23: advisory: GitHub Security Advisory GHSA-x68m-c7jf-2572 published
  • 2026-05-09: disclosed: CVE-2026-42051 published to NVD

References

Related threats