CVE-2026-41325General(getkirby / kirby)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch getkirby kirby systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint (`site/blueprints/users/...`). It is also possible to customize the permissions for each target model in the model blueprints (such as in `site/blueprints/pages/...`) using the `options` feature. The permissions and options together control the authorization of user actions. Kirby provides the `pages.create`, `files.create` and `users.create` permissions (among others). These permissions can again be set in the user blueprint and/or in the blueprint of the target model via `options`. Prior to versions 4.9.0 and 5.4.0, Kirby allowed to override the `options` during the creation of pages, files and users by injecting custom dynamic blueprint configuration into the model data. The injected `options` could include `'create' => true`, which then caused an override of the permissions and options configured by the site developer in the user and model blueprints. The problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. The patched versions have updated the normalization code that is used during the creation of pages, files and users to include a filter for the `blueprint` property. This prevents the injection of dynamic blueprint configuration into the creation request.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kirby

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-04-24); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
kirby

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1Mentions · 2026-04-28: 1Mentions · 2026-04-29: 1Patch / Workaround · 2026-04-29: 1Technical Details · 2026-04-28: 1Technical Details · 2026-04-29: 104-2404-2504-2804-29
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-241
General1
2026-04-251
General1
2026-04-281
Disclosure1
2026-04-291
Patch1
Full discourse4 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-41325 (CVSS 8.8) - Kirby CMS authorization bypass allows authenticated users to override permissions during page/file/user creation. Patched in v4.9.0 & v5.4.0. Update immediately. #CVE #PatchNow #CyberSecurity https://t.co/O8ijZugkdd

    Post summary

    Kirby CMS suffers from an authorization bypass (CVE-2026-41325) that lets authenticated users override permissions; patches are available in v4.9.0 and v5.4.0, and an immediate update is advised.

    0001042
    9 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-41325: CVE-2026-41325: Authorization Bypass via Blueprint Injection in Kirby CMS Kirby CMS versions prior to 4.9.0 and 5.4.0 suffer from an incorrect authorization vulnerability (CWE-863) allowing authenticated users to bypass resource creati... https://cvereports.com/reports/CVE-2026-41325

    Post summary

    The text discloses an authorization bypass vulnerability (CWE‑863) in older versions of Kirby CMS, with no PoC, exploits, or patches mentioned.

    0000019
    36 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-41325 Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CM… https://www.cve.org/CVERecord?id=CVE-2026-41325

    Post summary

    The text references CVE-2026-41325 for Kirby CMS but provides minimal detail and no evidence of exploitation, PoC, or remediation.

    00000104
    57.2K followersView on X
  • DailyCVE@dailycve
    General

    🔴 (Kirby CMS), Authorization Bypass, #CVE-2026-41325 (High) https://dailycve.com/kirby-cms-authorization-bypass-cve-2026-41325-high/

    Post summary

    The post announces a newly disclosed high‑severity authorization bypass vulnerability in Kirby CMS (CVE‑2026‑41325) but provides no further technical or operational details.

    0000043
    183 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgetkirbykirby---

Explore more