CVE-2026-42137: Getkirby Kirby

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API. This issue has been patched in versions 4.9.0 and 5.4.0.

Affected products

  • Getkirby Kirby: before 4.9.0 (fixed in 4.9.0); from 5.0.0, before 5.4.0 (fixed in 5.4.0)

Published 2026-05-09. Last modified 2026-07-24.