Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. getkirby/cms
  4. ›
  5. CVE-2026-44176

CVE-2026-44176: Kirby CMS's `pages.access` permission is not checked during rendering of page drafts

May 26, 2026

In affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post.

References

  • github.com/advisories/GHSA-2xw4-v2wx-hqq9
  • github.com/getkirby/kirby/releases/tag/4.9.1
  • github.com/getkirby/kirby/releases/tag/5.4.1
  • github.com/getkirby/kirby/security/advisories/GHSA-2xw4-v2wx-hqq9
  • nvd.nist.gov/vuln/detail/CVE-2026-44176

Code Behaviors & Features

Detect and mitigate CVE-2026-44176 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 4.9.1, all versions starting from 5.0.0 before 5.4.1

Fixed versions

  • 4.9.1
  • 5.4.1

Solution

Upgrade to versions 4.9.1, 5.4.1 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-862: Missing Authorization

Source file

packagist/getkirby/cms/CVE-2026-44176.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 23 Jun 2026 12:22:39 +0000.