Access Control Flaw in Kirby Content Management System by GetKirby
CVE-2026-45334
5.3MEDIUM
What is CVE-2026-45334?
A security flaw in Kirby CMS prior to version 4.9.1 and 5.4.1 allows low-privileged authenticated users to access sensitive information about other users currently editing content. The issue arises from the content-locking feature, which fails to appropriately check access permissions, leaking both the email addresses and identifiers of users locking a model for editing. This exposure can facilitate account enumeration, targeted phishing attempts, and potential credential stuffing attacks. The vulnerability has been patched in the latest versions.
Affected Version(s)
kirby < 4.9.1 < 4.9.1
kirby >= 5.0.0, < 5.4.1 < 5.0.0, 5.4.1
