PT-2026-50720 · Packagist+2 · Getkirby/Cms+1
CVE-2026-49274
·
Published
2026-06-18
·
Updated
2026-07-09
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Kirby versions prior to 4.9.4
Kirby versions prior to 5.4.4
Description
Authenticated users can confirm the existence of arbitrary pages and retrieve their title field values. This occurs when sites use the
pages field and user roles have the pages.access permission disabled. The issue stems from missing authorization in the backend logic of the page picker, which fails to validate if the user-provided parent page or site is accessible to the current user. This could lead to the disclosure of sensitive information.Recommendations
Update Kirby to version 4.9.4 or later.
Update Kirby to version 5.4.4 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Getkirby/Cms
Kirby