Information Disclosure in Kirby Modules Plugin by Medienbaecker
CVE-2026-63092
5.3MEDIUM
What is CVE-2026-63092?
The Kirby Modules plugin, developed by Medienbaecker, has a vulnerability that permits any authenticated user of the Kirby Panel to retrieve the plaintext license key by initiating a GET request to the modules/activate dialog endpoint. The plugin’s activate dialog handler fails to implement proper checks for administrative privileges, making the license key accessible due to the default permissions set for non-admin roles. As a result, attackers can exploit this vulnerability to activate the plugin on unauthorized third-party installations by using the disclosed license key.
Affected Version(s)
kirby-modules 0 <= 5.5.7
kirby-modules 0 <= 5.5.7
kirby-modules 315417e4fa9f18682e4382c9f44c04bd0913ce96
