Data Leakage in Kirby CMS Affects Authenticated Users
CVE-2026-42051
5.3MEDIUM
What is CVE-2026-42051?
Kirby, an open-source content management system, has a vulnerability in its system API endpoint that inadvertently exposes license information and installed version details to authenticated users. This misconfiguration can lead to unauthorized access to sensitive data. The issue has been rectified in the releases of versions 4.9.0 and 5.4.0, which ensure that such sensitive information is no longer accessible.
Affected Version(s)
kirby < 4.9.0 < 4.9.0
kirby >= 5.0.0, < 5.4.0 < 5.0.0, 5.4.0
