CVE-2026-42174

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement and deletion are not gated by user update permissions. This issue has been patched in versions 4.9.0 and 5.4.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:*
cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-09 04:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-42174

Mitre link : CVE-2026-42174

CVE.ORG link : CVE-2026-42174


JSON object : View

Products Affected

getkirby

  • kirby
CWE
CWE-862

Missing Authorization