CVE-2026-42069: high-severity vulnerability in getkirby kirby
Kirby: Read access to site, user and role information is not gated by permissions
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.1epss 0.4%
exploitation probability
0.4%top 68% of all CVEs
observed exploitation
nono source reports it
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, read access to site, user and role information is not gated by permissions. This issue has been patched in versions 4.9.0 and 5.4.0.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
getkirby · kirbyRelated CVEs — getkirby kirby
In the same product, most dangerous first.
CVE-2021-29460HIGHCross-site scripting (XSS) from unsanitized uploaded SVG filesEPSS 3.2%CVE-2026-44177HIGHKirby: Pre-authentication path traversal and PHP file inclusion during user lookupEPSS 1.8%CVE-2023-38490MEDIUMKirby XML External Entity (XXE) vulnerability in the XML data handlerEPSS 1.7%CVE-2020-26255MEDIUMPHP Phar archives could be uploaded and executed in KirbyEPSS 1.5%CVE-2023-38492MEDIUMKirby vulnerable to denial of service from unlimited password lengthsEPSS 1.2%CVE-2021-41252HIGHCross-site scripting (XSS) from writer field content in the site frontendEPSS 0.9%