Improper Authentication in Kirby - #VU150665

 

Improper Authentication in Kirby - #VU150665

Published: September 17, 2026


Vulnerability identifier: #VU150665
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to authenticate as another user.

The vulnerability exists due to improper authentication in the KirbyCmsAuth class when handling failed authentication challenge requests. A remote user can use a one-time code issued for their own account to authenticate as another user.

Exploitation requires control of an account whose email can be read and knowledge of the victim\'s email address.


Affected software

Kirby

Remediation

Install security update from vendor's website.

Kirby - addressed in versions 4.9.6, 5.6.0

External References

Related Security Bulletins