Information Disclosure in Kirby Modules Plugin by Medienbaecker
CVE-2026-63092

5.3MEDIUM

Key Information:

Vendor
CVE Published:
21 July 2026

What is CVE-2026-63092?

The Kirby Modules plugin, developed by Medienbaecker, has a vulnerability that permits any authenticated user of the Kirby Panel to retrieve the plaintext license key by initiating a GET request to the modules/activate dialog endpoint. The plugin’s activate dialog handler fails to implement proper checks for administrative privileges, making the license key accessible due to the default permissions set for non-admin roles. As a result, attackers can exploit this vulnerability to activate the plugin on unauthorized third-party installations by using the disclosed license key.

Affected Version(s)

kirby-modules 0 <= 5.5.7

kirby-modules 0 <= 5.5.7

kirby-modules 315417e4fa9f18682e4382c9f44c04bd0913ce96

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

@rayyb0t
VulnCheck
.