Exposure of Sensitive System Information to an Unauthorized Control Sphere in Kirby - CVE-2026-69127

 

Exposure of Sensitive System Information to an Unauthorized Control Sphere in Kirby - CVE-2026-69127

Published: July 20, 2026 / Updated: August 13, 2026


Vulnerability identifier: #VU138445
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-69127
CWE-ID: CWE-497
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive system information.

The vulnerability exists due to exposure of sensitive system information in the REST API error handler when handling crafted API requests that trigger internal errors. A remote attacker can send a specially crafted request to disclose sensitive system information.

The issue can expose the full filesystem path of the installation, and unauthenticated API access is sufficient when the REST API is enabled.


Affected software

Kirby

How to mitigate CVE-2026-69127

Install security update from vendor's website.

Kirby - addressed in versions 4.9.5, 5.5.2

External References

Related Security Bulletins