Medium severityNVD Advisory· Published Jul 9, 2026· Updated Jul 14, 2026
CVE-2026-49274
CVE-2026-49274
Description
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the pages field with roles that have the pages.access permission disabled allowed authenticated users to provide an inaccessible parent page or site to the page picker backend and confirm arbitrary page existence and retrieve title field values. This issue is fixed in versions 4.9.4 and 5.4.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
getkirby/cmsPackagist | < 4.9.4 | 4.9.4 |
getkirby/cmsPackagist | >= 5.0.0-alpha.1, < 5.4.4 | 5.4.4 |
Affected products
1Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-23q2-54qv-rq5xghsaADVISORY
- github.com/getkirby/kirby/releases/tag/4.9.4nvdWEB
- github.com/getkirby/kirby/releases/tag/5.4.4nvdWEB
- github.com/getkirby/kirby/security/advisories/GHSA-23q2-54qv-rq5xnvdWEB
- github.com/getkirby/kirby/commit/1ae575da24e1b1cb8803a031d37eff14606d7c55nvd
- github.com/getkirby/kirby/commit/3bad37117adf2013548a784f820ddb2d8317333cnvd
- github.com/getkirby/kirby/commit/3f4398cdcf9f50f84fdac52ad78a7a85fb31589fnvd
- github.com/getkirby/kirby/commit/bffffce6c081f69c46163cc89b1fd18ccf2a18d1nvd
News mentions
1- Kirby CMS: Seven Bugs Patched in One Advisory, Including Critical Auth BypassVypr Intelligence · Jun 18, 2026