CVE 5.8 MEDIUM

Kirby is missing permission checks in the content changes API_CVE-2026-21896

5.8 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N

Description

Kirby is an open-source content management system. From versions 5.0.0 to 5.2.1, Kirby is missing permission checks in the content changes API. This vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the update permission with the intent to prevent modifications to site content. This vulnerability does not affect those who have not altered the deviated from default user permissions. This issue has been patched in version 5.2.2.

Basic Information

ID CVE-2026-21896
Source GitHub_M
Published Jan 8, 2026 at 18:09

Affected Product

Vendor getkirby
Product kirby
Version >= 5.0.0, < 5.2.2
Affected Versions getkirby kirby >= 5.0.0, < 5.2.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.