Missing Authorization in Kirby - CVE-2026-54004
Published: July 20, 2026
Kirby
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization in clean file redirects for top-level draft files when handling requests for clean file URLs. A remote attacker can request a known clean file URL to disclose sensitive information.
Only files stored in top-level drafts are affected, and exploitation requires knowledge of the full clean file URL.