5.3
CVE-2026-49274
- EPSS 0.28%
- Veröffentlicht 09.07.2026 18:38:32
- Zuletzt bearbeitet 14.07.2026 02:16:55
- CVE-Watchlists
- Unerledigt
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the pages field with roles that have the pages.access permission disabled allowed authenticated users to provide an inaccessible parent page or site to the page picker backend and confirm arbitrary page existence and retrieve title field values. This issue is fixed in versions 4.9.4 and 5.4.4.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellergetkirby
≫
Produkt
kirby
Version
< 4.9.4
Status
affected
Version
>= 5.0.0, < 5.4.4
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.193 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://github.com/getkirby/kirby/security/advisories/GHSA-23q2-54qv-rq5x
https://github.com/getkirby/kirby/commit/1ae575da24e1b1cb8803a031d37eff14606d7c55
https://github.com/getkirby/kirby/commit/3bad37117adf2013548a784f820ddb2d8317333c
https://github.com/getkirby/kirby/commit/3f4398cdcf9f50f84fdac52ad78a7a85fb31589f
https://github.com/getkirby/kirby/commit/bffffce6c081f69c46163cc89b1fd18ccf2a18d1
https://github.com/getkirby/kirby/releases/tag/4.9.4
https://github.com/getkirby/kirby/releases/tag/5.4.4