Authorization bypass through user-controlled key in Kirby - #VU150661

 

Authorization bypass through user-controlled key in Kirby - #VU150661

Published: September 17, 2026


Vulnerability identifier: #VU150661
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in the `files`, `pages`, and `users` field model-resolution logic when resolving IDs stored in content files into models for Panel views. A remote user can write the ID of an inaccessible page, file, or user into an updatable field to disclose sensitive information.

For files, the disclosed media URL includes the token that authorizes access to the file.


Affected software

Kirby

Remediation

Install security update from vendor's website.

Kirby - addressed in versions 4.9.6, 5.6.0

External References

Related Security Bulletins