PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-42051 getkirby CVE debrief

CVE-2026-42051 is an information-disclosure issue in Kirby CMS. According to the supplied advisory and NVD record, authenticated users could access system API data that reveals license details and the installed version in versions prior to 4.9.0 and 5.4.0. The issue is patched in those releases. The reported severity is medium, consistent with limited confidentiality impact and no direct integrity or availability impact in the supplied data.

Vendor
getkirby
Product
kirby
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-09
Original CVE updated
2026-07-24
Advisory published
2026-05-09
Advisory updated
2026-07-24

Who should care

Kirby administrators, hosting providers, and security teams responsible for sites running Kirby versions earlier than 4.9.0 or 5.4.0, especially where authenticated users should not be able to view license or version metadata.

Technical summary

The supplied sources describe a missing-authorization condition affecting a Kirby system API endpoint. The weakness is mapped to CWE-862 in the advisory metadata. Impact is limited to disclosure of license data and the installed version to authenticated users. The fix is included in Kirby 4.9.0 and 5.4.0, as referenced by the official release tags and GitHub security advisory.

Defensive priority

Medium. Prioritize patching if you expose Kirby to multiple authenticated users, use license/version metadata as sensitive operational information, or rely on strict internal access boundaries.

Recommended defensive actions

  • Upgrade Kirby to 4.9.0 or 5.4.0 or later, depending on your release line.
  • Review whether authenticated users can reach the affected system API endpoint in your deployment.
  • Confirm that license and installed-version metadata are no longer exposed after upgrading.
  • Inventory all Kirby instances to identify any versions earlier than the fixed releases.
  • Check application logs and access controls for unusual authenticated access to system API resources around the time of remediation.

Evidence notes

This debrief is based only on the supplied NVD record and GitHub-hosted Kirby security/advisory references. The NVD entry cites the Kirby release tags for 4.9.0 and 5.4.0 and the GitHub security advisory GHSA-x68m-c7jf-2572. The supplied timeline shows CVE publication and modification at 2026-05-09T04:16:22.110Z. No KEV date or ransomware-campaign metadata was supplied.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-42051 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-42051

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-42051 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42051

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.