CVE-2026-42137

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API. This issue has been patched in versions 4.9.0 and 5.4.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:*
cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-09 04:16

Updated : 2026-07-24 19:10


NVD link : CVE-2026-42137

Mitre link : CVE-2026-42137

CVE.ORG link : CVE-2026-42137


JSON object : View

Products Affected

getkirby

  • kirby
CWE
CWE-862

Missing Authorization

CWE-863

Incorrect Authorization