Junglewise Threat Intelligence

CVE-2026-42137: Kirby CMS incorrect authorization in Panel and REST API permissions

CVE-2026-42137 · Severity: medium · CVSS 6.5 · Published 2026-05-09

Technologies: Kirby, Kirby CMS. Vendors: Kirby.

Executive brief

Kirby, an open-source content management system, contains a vulnerability where certain access controls for pages and files are not consistently enforced. This allows authenticated users, such as staff with limited accounts, to view sensitive files or page listings they are officially restricted from seeing. While attackers cannot modify or delete content through this flaw, it can lead to the exposure of private internal data or intellectual property.

Technical details

Kirby CMS is vulnerable to missing and incorrect authorization checks (CWE-862, CWE-863) within its Panel and REST API. Specifically, the 'pages.access', 'pages.list', 'files.access', and 'files.list' permissions are not consistently applied when filtering collections or related models. An authenticated attacker with low privileges can exploit this to view restricted page metadata, file listings, and parent/sibling relationships that should be hidden based on their role's blueprint configuration. The vulnerability affects the REST API's handling of children, drafts, and search routes, as well as the Panel's 'changes' dialog and image previews. The issue is resolved in versions 4.9.0 and 5.4.0 by implementing consistent '$model->isListable()' checks.

Affected products

  • Kirby Kirby CMS < 4.9.0, 5.0.0 to < 5.4.0

Timeline

  • 2026-04-23: patched: Versions 4.9.0 and 5.4.0 released
  • 2026-04-23: advisory: GitHub Security Advisory GHSA-85x2-r8xv-ww8c published
  • 2026-05-09: disclosed: CVE-2026-42137 published to NVD

References

Related threats