Access Control Flaw in Kirby CMS Affecting Content Permissions
CVE-2026-44176

6MEDIUM

Key Information:

Vendor

Getkirby

Status
Vendor
CVE Published:
16 July 2026

What is CVE-2026-44176?

Kirby CMS, an open-source content management system, has a vulnerability affecting earlier versions (before 4.9.1 and 5.4.1), which fails to properly check user permissions during the rendering of page drafts. This oversight permits authenticated users to access drafts even if they lack the required permissions. If an attacker knows the path to an existing draft, they can retrieve sensitive information intended for privileged users, potentially undermining content confidentiality. This issue has been addressed in releases 4.9.1 and 5.4.1.

Affected Version(s)

kirby < 4.9.1 < 4.9.1

kirby >= 5.0.0, < 5.4.1 < 5.0.0, 5.4.1

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.