PT-2026-44153 · Packagist+2 · Getkirby/Cms+1

CVE-2026-45334

·

Published

2026-05-27

·

Updated

2026-07-16

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kirby versions prior to 4.9.1 Kirby versions prior to 5.4.1
Description Missing authorization in the content-locking feature allows authenticated users to access sensitive information. The system records which user has a model open for editing to prevent conflicting edits and displays the user's identity in the Panel UI. However, the locking user's email address and identifier are included in every Panel view payload and in error responses without verifying the requesting user's access permissions. This allows a low-privilege authenticated user, specifically those with roles configured with users.access: false or users.list: false, to obtain the email addresses and internal identifiers of other users, including administrators, who have a model open for editing. This information can be used for admin account enumeration, targeted phishing, and credential-stuffing attacks.
Recommendations Update Kirby to version 4.9.1 or later. Update Kirby to version 5.4.1 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45334
GHSA-39VQ-49QM-R2MC

Affected Products

Getkirby/Cms
Kirby