Missing Authorization in Kirby - #VU127192
Published: April 23, 2026
Kirby
Detailed vulnerability description
The vulnerability allows a remote user to modify user avatars without authorization.
The vulnerability exists due to missing authorization in user avatar management when handling avatar creation, replacement, or deletion requests. A remote user can create, replace, or delete a user avatar to modify user avatars without authorization.
The issue affects sites where the acting user's role is not permitted to update user information, but file permissions still allow avatar-related actions.