Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement and deletion are not gated by user update permissions. This issue has been patched in versions 4.9.0 and 5.4.0.
References
| Link | Resource |
|---|---|
| https://github.com/getkirby/kirby/releases/tag/4.9.0 | Release Notes |
| https://github.com/getkirby/kirby/releases/tag/5.4.0 | Release Notes |
| https://github.com/getkirby/kirby/security/advisories/GHSA-39cp-6679-8xv2 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
18 May 2026, 13:00
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Getkirby kirby
Getkirby |
|
| CPE | cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
| References | () https://github.com/getkirby/kirby/releases/tag/4.9.0 - Release Notes | |
| References | () https://github.com/getkirby/kirby/releases/tag/5.4.0 - Release Notes | |
| References | () https://github.com/getkirby/kirby/security/advisories/GHSA-39cp-6679-8xv2 - Patch, Vendor Advisory |
09 May 2026, 04:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-09 04:16
Updated : 2026-05-18 13:00
NVD link : CVE-2026-42174
Mitre link : CVE-2026-42174
CVE.ORG link : CVE-2026-42174
JSON object : View
Products Affected
getkirby
- kirby
CWE
CWE-862
Missing Authorization
