External Initialization of Trusted Variables or Data Stores in Kirby - CVE-2026-54003
Published: July 20, 2026
Kirby
Detailed vulnerability description
The vulnerability allows a remote attacker to create an administrative account.
The vulnerability exists due to external initialization of trusted variables or data stores in the Panel installation logic and REST API authentication flow when handling installation requests behind a reverse proxy that sets the Forwarded, X-Client-IP, or X-Real-IP header. A remote attacker can send a crafted installation request to create an administrative account.
Only installations with no configured user accounts on publicly accessible servers behind affected reverse proxy setups are vulnerable.