CVE-2026-42137
Kirby: `pages.access/list` and `files.access/list` permissions are not consistently checked in the REST API and changes dialog
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API. This issue has been patched in versions 4.9.0 and 5.4.0.
| CWE | CWE-862 CWE-863 |
| Vendor | getkirby |
| Product | kirby |
| Published | May 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for getkirby kirby
Be the first to know when new unknown vulnerabilities affecting getkirby kirby are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
getkirby / kirby
< 4.9.0 >= 5.0.0, < 5.4.0