High severityNVD Advisory· Published Jul 9, 2026· Updated Jul 14, 2026
CVE-2026-54005
CVE-2026-54005
Description
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites where a role has the pages.access permission disabled allowed authenticated users who know or guess page IDs or UUIDs to retrieve page information, including full content and metadata, for arbitrary published pages through the /api/site/find route without authorization to access those pages. This issue is fixed in versions 4.9.4 and 5.4.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
getkirby/cmsPackagist | < 4.9.4 | 4.9.4 |
getkirby/cmsPackagist | >= 5.0.0-alpha.1, < 5.4.4 | 5.4.4 |
Affected products
1Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-r3w8-2c5r-h9j9ghsaADVISORY
- github.com/getkirby/kirby/releases/tag/4.9.4nvdWEB
- github.com/getkirby/kirby/releases/tag/5.4.4nvdWEB
- github.com/getkirby/kirby/security/advisories/GHSA-r3w8-2c5r-h9j9nvdWEB
- github.com/getkirby/kirby/commit/a16dbd4329293c2c4b9a375d2badcb27c6337004nvd
- github.com/getkirby/kirby/commit/b22d0b64b6478ce6871dc7ec3368d7afaf078688nvd
News mentions
1- Kirby CMS: Seven Bugs Patched in One Advisory, Including Critical Auth BypassVypr Intelligence · Jun 18, 2026