Vulnerability in Kirby CMS Affecting Upload Functionality
CVE-2026-71415
7.1HIGH
What is CVE-2026-71415?
A vulnerability in Kirby CMS, versions 5.0.0 through 5.5.2, exists due to improper authorization checks in the REST API's chunk upload handler. An authenticated user, who has access.panel permission but lacks files.create, files.replace, and user/users.update permissions, can exploit this flaw. By sending requests with an Upload-Length header, they can leave unfinished file chunks in the site’s cache for up to 24 hours. This behavior could lead to the consumption of temporary storage by the attacker, preventing legitimate users from uploading files and disrupting site functionalities. The issue has been addressed and patched in version 5.5.2.
Affected Version(s)
kirby >= 5.0.0, < 5.5.2
