Missing Authorization in Kirby - CVE-2026-42051

 

Missing Authorization in Kirby - CVE-2026-42051

Published: April 23, 2026


Vulnerability identifier: #VU127197
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-42051
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in the /api/system REST API endpoint when handling authenticated requests. A remote user can send a request to the endpoint to disclose sensitive information.

The exposed information includes the installed Kirby version and the status, type and code of the installed license.


Affected software

Kirby

How to mitigate CVE-2026-42051

Install security update from vendor's website.

Kirby - addressed in versions 4.9.0, 5.4.0

External References

Related Security Bulletins