Vulnerability in Kirby CMS Affecting Upload Functionality
CVE-2026-71415

7.1HIGH

Key Information:

Vendor

Getkirby

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-71415?

A vulnerability in Kirby CMS, versions 5.0.0 through 5.5.2, exists due to improper authorization checks in the REST API's chunk upload handler. An authenticated user, who has access.panel permission but lacks files.create, files.replace, and user/users.update permissions, can exploit this flaw. By sending requests with an Upload-Length header, they can leave unfinished file chunks in the site’s cache for up to 24 hours. This behavior could lead to the consumption of temporary storage by the attacker, preventing legitimate users from uploading files and disrupting site functionalities. The issue has been addressed and patched in version 5.5.2.

Affected Version(s)

kirby >= 5.0.0, < 5.5.2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.