Kirby is an open-source content management system. Prior to 4.9.4 and from 5.4.4, Kirby sites with no configured user accounts that run on publicly accessible servers behind a reverse proxy setting the Forwarded, X-Client-IP, or X-Real-IP request header could allow remote attackers to install the Panel and create the first admin user because local-IP checks trusted those headers incorrectly. This issue is fixed in versions 4.9.4 and 5.4.4.
CVSS
No CVSS.
References
Configurations
No configuration.
History
09 Jul 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-09 19:17
Updated : 2026-07-10 15:49
NVD link : CVE-2026-54003
Mitre link : CVE-2026-54003
CVE.ORG link : CVE-2026-54003
JSON object : View
Products Affected
No product.
CWE
CWE-454
External Initialization of Trusted Variables or Data Stores
