Access Control Flaw in Kirby CMS Affecting Content Permissions
CVE-2026-44176
6MEDIUM
What is CVE-2026-44176?
Kirby CMS, an open-source content management system, has a vulnerability affecting earlier versions (before 4.9.1 and 5.4.1), which fails to properly check user permissions during the rendering of page drafts. This oversight permits authenticated users to access drafts even if they lack the required permissions. If an attacker knows the path to an existing draft, they can retrieve sensitive information intended for privileged users, potentially undermining content confidentiality. This issue has been addressed in releases 4.9.1 and 5.4.1.
Affected Version(s)
kirby < 4.9.1 < 4.9.1
kirby >= 5.0.0, < 5.4.1 < 5.0.0, 5.4.1
