External Initialization of Trusted Variables or Data Stores in Kirby - CVE-2026-54003

 

External Initialization of Trusted Variables or Data Stores in Kirby - CVE-2026-54003

Published: July 20, 2026


Vulnerability identifier: #VU138437
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54003
CWE-ID: CWE-454
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to create an administrative account.

The vulnerability exists due to external initialization of trusted variables or data stores in the Panel installation logic and REST API authentication flow when handling installation requests behind a reverse proxy that sets the Forwarded, X-Client-IP, or X-Real-IP header. A remote attacker can send a crafted installation request to create an administrative account.

Only installations with no configured user accounts on publicly accessible servers behind affected reverse proxy setups are vulnerable.


Affected software

Kirby

How to mitigate CVE-2026-54003

Install security update from vendor's website.

Kirby - addressed in versions 4.9.4, 5.4.4

External References

Related Security Bulletins