CVE-2026-42069

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, read access to site, user and role information is not gated by permissions. This issue has been patched in versions 4.9.0 and 5.4.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:*
cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:*

History

18 May 2026, 13:00

Type Values Removed Values Added
References () https://github.com/getkirby/kirby/releases/tag/4.9.0 - () https://github.com/getkirby/kirby/releases/tag/4.9.0 - Release Notes
References () https://github.com/getkirby/kirby/releases/tag/5.4.0 - () https://github.com/getkirby/kirby/releases/tag/5.4.0 - Release Notes
References () https://github.com/getkirby/kirby/security/advisories/GHSA-2h7v-4372-f6x2 - () https://github.com/getkirby/kirby/security/advisories/GHSA-2h7v-4372-f6x2 - Patch, Vendor Advisory
First Time Getkirby kirby
Getkirby
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:*

09 May 2026, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-09 04:16

Updated : 2026-05-18 13:00


NVD link : CVE-2026-42069

Mitre link : CVE-2026-42069

CVE.ORG link : CVE-2026-42069


JSON object : View

Products Affected

getkirby

  • kirby
CWE
CWE-862

Missing Authorization