PT-2026-50720 · Packagist+2 · Getkirby/Cms+1

CVE-2026-49274

·

Published

2026-06-18

·

Updated

2026-07-09

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kirby versions prior to 4.9.4 Kirby versions prior to 5.4.4
Description Authenticated users can confirm the existence of arbitrary pages and retrieve their title field values. This occurs when sites use the pages field and user roles have the pages.access permission disabled. The issue stems from missing authorization in the backend logic of the page picker, which fails to validate if the user-provided parent page or site is accessible to the current user. This could lead to the disclosure of sensitive information.
Recommendations Update Kirby to version 4.9.4 or later. Update Kirby to version 5.4.4 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49274
GHSA-23Q2-54QV-RQ5X

Affected Products

Getkirby/Cms
Kirby