Executive brief
Kirby is a content management system used to build and manage websites. A vulnerability exists where new installations or sites without existing user accounts can be hijacked by remote attackers. If the server is behind certain network configurations, an attacker can bypass security checks to access the setup panel and create an administrative account, effectively taking full control of the website.
Technical details
A vulnerability in Kirby's `isLocal()` check in the `Http\Environment` component incorrectly trusts several HTTP request headers, including `Forwarded`, `X-Client-IP`, and `X-Real-IP`. On sites with no configured user accounts, Kirby allows administrative Panel installation if the request appears to originate from a local IP. An attacker can spoof these headers to bypass the local-IP restriction when the site is hosted behind a reverse proxy that passes these headers. This allows the attacker to create the initial admin user and gain full control of the CMS. The issue is fixed in versions 4.9.4 and 5.4.4.
Affected products
- getkirby Kirby < 4.9.4, >= 5.0.0, < 5.4.4
Timeline
- 2026-05-28: patched: Fix merged into development branch
- 2026-06-17: advisory: Security releases 4.9.4 and 5.4.4 published
- 2026-07-09: disclosed: CVE-2026-54003 published
References
- https://github.com/getkirby/kirby/commit/1c7fee90e49153cf9ca4a6ec17481d25fbedc48d
- https://github.com/getkirby/kirby/commit/3423f66c01dbc0455862e23ee699d2aa469f3234
- https://github.com/getkirby/kirby/commit/66a3a14bf0892d320723ba766cd5f1d33a51d15b
- https://github.com/getkirby/kirby/commit/ab992dc149610b90e337c2955ab6ccb7f72ffb3a
- https://github.com/getkirby/kirby/pull/8166
- https://github.com/getkirby/kirby/releases/tag/4.9.4
- https://github.com/getkirby/kirby/releases/tag/5.4.4