Access Control Flaw in Kirby Content Management System by GetKirby
CVE-2026-45334

5.3MEDIUM

Key Information:

Vendor

Getkirby

Status
Vendor
CVE Published:
16 July 2026

What is CVE-2026-45334?

A security flaw in Kirby CMS prior to version 4.9.1 and 5.4.1 allows low-privileged authenticated users to access sensitive information about other users currently editing content. The issue arises from the content-locking feature, which fails to appropriately check access permissions, leaking both the email addresses and identifiers of users locking a model for editing. This exposure can facilitate account enumeration, targeted phishing attempts, and potential credential stuffing attacks. The vulnerability has been patched in the latest versions.

Affected Version(s)

kirby < 4.9.1 < 4.9.1

kirby >= 5.0.0, < 5.4.1 < 5.0.0, 5.4.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.