SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-49274

MEDIUM · CVSS 5.3 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

Kirby CMS versions prior to 4.9.4 and 5.4.4 are vulnerable to a permissions issue that allows authenticated users to exploit the pages field, enabling them to confirm the existence of arbitrary pages and retrieve their title field values, even if they lack access permissions. This could lead to information disclosure, potentially exposing sensitive content structure details. Organizations using affected versions of Kirby should prioritize upgrading to the latest versions to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-49274
Severity
MEDIUM
CVSS
5.3
EPSS
0.27%

Original NVD Description

Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the pages field with roles that have the pages.access permission disabled allowed authenticated users to provide an inaccessible parent page or site to the page picker backend and confirm arbitrary page existence and retrieve title field values. This issue is fixed in versions 4.9.4 and 5.4.4.