Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement and deletion are not gated by user update permissions. This issue has been patched in versions 4.9.0 and 5.4.0.
References
| Link | Resource |
|---|---|
| https://github.com/getkirby/kirby/releases/tag/4.9.0 | Release Notes |
| https://github.com/getkirby/kirby/releases/tag/5.4.0 | Release Notes |
| https://github.com/getkirby/kirby/security/advisories/GHSA-39cp-6679-8xv2 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-05-09 04:16
Updated : 2026-07-24 21:10
NVD link : CVE-2026-42174
Mitre link : CVE-2026-42174
CVE.ORG link : CVE-2026-42174
JSON object : View
Products Affected
getkirby
- kirby
CWE
CWE-862
Missing Authorization
