Access Control Weakness in Kirby CMS by Getkirby
CVE-2026-42069
7.1HIGH
What is CVE-2026-42069?
The Kirby CMS, an open-source content management system, experienced a significant access control vulnerability prior to versions 4.9.0 and 5.4.0. This flaw allowed unauthorized users to gain read access to site, user, and role information without appropriate permissions. To mitigate the risk, users are advised to upgrade to the patched versions immediately.
Affected Version(s)
kirby < 4.9.0 < 4.9.0
kirby >= 5.0.0, < 5.4.0 < 5.0.0, 5.4.0
