Data Leakage in Kirby CMS Affects Authenticated Users
CVE-2026-42051

5.3MEDIUM

Key Information:

Vendor

Getkirby

Status
Vendor
CVE Published:
9 May 2026

What is CVE-2026-42051?

Kirby, an open-source content management system, has a vulnerability in its system API endpoint that inadvertently exposes license information and installed version details to authenticated users. This misconfiguration can lead to unauthorized access to sensitive data. The issue has been rectified in the releases of versions 4.9.0 and 5.4.0, which ensure that such sensitive information is no longer accessible.

Affected Version(s)

kirby < 4.9.0 < 4.9.0

kirby >= 5.0.0, < 5.4.0 < 5.0.0, 5.4.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.