PT-2026-44153 · Packagist+2 · Getkirby/Cms+1
CVE-2026-45334
·
Published
2026-05-27
·
Updated
2026-07-16
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Kirby versions prior to 4.9.1
Kirby versions prior to 5.4.1
Description
Missing authorization in the content-locking feature allows authenticated users to access sensitive information. The system records which user has a model open for editing to prevent conflicting edits and displays the user's identity in the Panel UI. However, the locking user's email address and identifier are included in every Panel view payload and in error responses without verifying the requesting user's access permissions. This allows a low-privilege authenticated user, specifically those with roles configured with
users.access: false or users.list: false, to obtain the email addresses and internal identifiers of other users, including administrators, who have a model open for editing. This information can be used for admin account enumeration, targeted phishing, and credential-stuffing attacks.Recommendations
Update Kirby to version 4.9.1 or later.
Update Kirby to version 5.4.1 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Getkirby/Cms
Kirby