Incorrect authorization in Kirby - #VU127193
Published: April 23, 2026
Kirby
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to incorrect authorization in the Panel and REST API when handling requests for page and file listings and related models. A remote user can send crafted requests to access non-listable pages or files and disclose sensitive information.
The issue affects sites where page or file access or list permissions are disabled for a role through user blueprints, model blueprints, or both. Write actions are not affected.