PatchSiren cyber security CVE debrief
CVE-2026-54005 getkirby CVE debrief
CVE-2026-54005 is a high-severity vulnerability in Kirby CMS that allows authenticated users to retrieve page information without authorization. The issue was fixed in versions 4.9.4 and 5.4.4. This vulnerability affects users with public sites or sensitive information, who should prioritize patching to prevent unauthorized access to page information. The vulnerability class is related to improper authorization, allowing attackers to bypass access controls.
- Vendor
- getkirby
- Product
- kirby
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-09
- Original CVE updated
- 2026-07-14
- Advisory published
- 2026-07-09
- Advisory updated
- 2026-07-14
Who should care
Users of Kirby CMS, especially those with public sites or sensitive information, should prioritize patching to prevent unauthorized access to page information. This includes site administrators, security teams, and developers responsible for maintaining Kirby CMS installations. Additionally, users with high-security requirements or sensitive data should review and restrict access to the /api/site/find route.
Technical summary
Kirby CMS versions prior to 4.9.4 and 5.4.4 have a vulnerability that allows authenticated users to retrieve page information, including full content and metadata, for arbitrary published pages through the /api/site/find route without authorization to access those pages. The issue arises from insufficient access controls on the /api/site/find route, which can be exploited by authenticated users to access sensitive information.
Defensive priority
High priority should be given to patching Kirby CMS to prevent unauthorized access to sensitive information. Site administrators should review and restrict access to the /api/site/find route and monitor for suspicious activity.
Recommended defensive actions
- Apply patches or updates to Kirby CMS versions 4.9.4 or 5.4.4
- Review and restrict access to the /api/site/find route
- Monitor for suspicious activity related to page information disclosure
- Verify page access controls and ensure proper authorization
- Conduct a thorough review of site security and configuration
- Implement compensating controls for exposed systems while remediation is scheduled and verified
Evidence notes
The CVE record was published on 2026-07-09T19:17:06.400Z and was last modified on 2026-07-10T15:49:19.093Z. The NVD entry is currently Deferred. The vulnerability affects Kirby CMS versions prior to 4.9.4 and 5.4.4. Authenticated users can retrieve page information, including full content and metadata, for arbitrary published pages through the /api/site/find route without authorization to access those pages. The issue was fixed in versions 4.9.4 and 5.4.4. Evidence limits suggest verifying page access controls and monitoring for suspicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-54005 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-54005
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-54005 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54005
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/getkirby/kirby/commit/a16dbd4329293c2c4b9a375d2badcb27c6337004
-
Source reference
Unverified legacy reference
URL: https://github.com/getkirby/kirby/commit/b22d0b64b6478ce6871dc7ec3368d7afaf078688
-
Source reference
Unverified legacy reference
URL: https://github.com/getkirby/kirby/releases/tag/4.9.4
-
Source reference
Unverified legacy reference
URL: https://github.com/getkirby/kirby/releases/tag/5.4.4
-
Source reference
Unverified legacy reference
URL: https://github.com/getkirby/kirby/security/advisories/GHSA-r3w8-2c5r-h9j9
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.