External Initialization of Trusted Variables or Data Stores in Kirby - CVE-2026-54003

 

External Initialization of Trusted Variables or Data Stores in Kirby - CVE-2026-54003

Published: July 20, 2026


Vulnerability identifier: #VU138437
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2026-54003
CWE-ID: CWE-454
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Ian Stewart
Affected software:
Kirby

Detailed vulnerability description

The vulnerability allows a remote attacker to create an administrative account.

The vulnerability exists due to external initialization of trusted variables or data stores in the Panel installation logic and REST API authentication flow when handling installation requests behind a reverse proxy that sets the Forwarded, X-Client-IP, or X-Real-IP header. A remote attacker can send a crafted installation request to create an administrative account.

Only installations with no configured user accounts on publicly accessible servers behind affected reverse proxy setups are vulnerable.


How to mitigate CVE-2026-54003

Install security update from vendor's website.

Sources