Missing Authorization in Kirby - #VU127198
Published: April 23, 2026
Kirby
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in site, user, and role information access controls when handling authenticated Panel requests. A remote user can access site, user, and role information to disclose sensitive information.
Write actions are not affected.