CVE-2026-42051

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, the system API endpoint leaks license data and installed version to authenticated users. This issue has been patched in versions 4.9.0 and 5.4.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:*
cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:*

History

24 Jul 2026, 21:10

Type Values Removed Values Added
Summary
  • (es) Kirby es un sistema de gestión de contenido de código abierto. Antes de las versiones 4.9.0 y 5.4.0, el endpoint de la API del sistema filtra datos de licencia y la versión instalada a usuarios autenticados. Este problema ha sido parcheado en las versiones 4.9.0 y 5.4.0.

18 May 2026, 13:01

Type Values Removed Values Added
References () https://github.com/getkirby/kirby/releases/tag/4.9.0 - () https://github.com/getkirby/kirby/releases/tag/4.9.0 - Release Notes
References () https://github.com/getkirby/kirby/releases/tag/5.4.0 - () https://github.com/getkirby/kirby/releases/tag/5.4.0 - Release Notes
References () https://github.com/getkirby/kirby/security/advisories/GHSA-x68m-c7jf-2572 - () https://github.com/getkirby/kirby/security/advisories/GHSA-x68m-c7jf-2572 - Patch, Vendor Advisory
First Time Getkirby kirby
Getkirby
CPE cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

09 May 2026, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-09 04:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-42051

Mitre link : CVE-2026-42051

CVE.ORG link : CVE-2026-42051


JSON object : View

Products Affected

getkirby

  • kirby
CWE
CWE-862

Missing Authorization