Junglewise Threat Intelligence

CVE-2026-42069: Kirby CMS missing authorization for site and user information

CVE-2026-42069 · Severity: high · CVSS 6.5 · Published 2026-05-09

Technologies: Kirby, Kirby CMS. Vendors: Kirby.

Executive brief

Kirby, a popular content management system, was found to have a security flaw where certain administrative information was not properly protected. An authenticated user with low-level access could view sensitive site configurations, user lists, and role details that they should not be able to see. This could lead to the exposure of private user data and internal system structures, though it does not allow the attacker to modify any information.

Technical details

A missing authorization vulnerability (CWE-862) exists in Kirby CMS where read access to the site model, user accounts, and role definitions is not governed by the system's permission framework. While write actions were correctly restricted, the 'site.access', 'user.access', and 'user.list' permissions were not implemented or checked in affected versions. An authenticated attacker with Panel access can exploit this to retrieve sensitive information about other users, their roles, and site-wide configurations. The issue is resolved in versions 4.9.0 and 5.4.0 by introducing and enforcing these missing permission checks.

Affected products

  • Kirby Kirby CMS <= 4.8.0, 5.0.0 to 5.3.3

Timeline

  • 2026-04-23: patched: Versions 4.9.0 and 5.4.0 released
  • 2026-04-23: advisory: GitHub Security Advisory published
  • 2026-05-09: disclosed: CVE-2026-42069 published to NVD

References

Related threats