7.1
CVE-2026-54005
- EPSS 0.27%
- Veröffentlicht 09.07.2026 18:47:02
- Zuletzt bearbeitet 14.07.2026 02:16:55
- CVE-Watchlists
- Unerledigt
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites where a role has the pages.access permission disabled allowed authenticated users who know or guess page IDs or UUIDs to retrieve page information, including full content and metadata, for arbitrary published pages through the /api/site/find route without authorization to access those pages. This issue is fixed in versions 4.9.4 and 5.4.4.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellergetkirby
≫
Produkt
kirby
Version
< 4.9.4
Status
affected
Version
>= 5.0.0, < 5.4.4
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.185 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 7.1 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://github.com/getkirby/kirby/releases/tag/4.9.4
https://github.com/getkirby/kirby/releases/tag/5.4.4
https://github.com/getkirby/kirby/security/advisories/GHSA-r3w8-2c5r-h9j9
https://github.com/getkirby/kirby/commit/a16dbd4329293c2c4b9a375d2badcb27c6337004
https://github.com/getkirby/kirby/commit/b22d0b64b6478ce6871dc7ec3368d7afaf078688