CVE Explorer
CVE-2026-21896
Kirby is an open-source content management system. From versions 5.0.0 to 5.2.1, Kirby is missing permission checks in the content changes API. This vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the update permission with the intent to prevent modifications to site content. This vulnerability does not affect those who have not altered the deviated from default user permissions. This
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"kirby","vendor":"getkirby","versions":[{"status":"affected","version":">= 5.0.0, < 5.2.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6faa54d44a82a8521fe0b2b23ec4876fa17c4ef88558bf3267ea0ec1b06ccdaf · sha256:beff78847401b635… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":5.8,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"ACTIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6faa54d44a82a8521fe0b2b23ec4876fa17c4ef88558bf3267ea0ec1b06ccdaf · sha256:beff78847401b635… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6faa54d44a82a8521fe0b2b23ec4876fa17c4ef88558bf3267ea0ec1b06ccdaf · sha256:beff78847401b635… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/getkirby/kirby/commit/f5ce1347b427b819bf193acf11fd0da232f7af47","tags":["x_refsource_MISC"],"url":"https://github.com/getkirby/kirby/commit/f5ce1347b427b819bf193acf11fd0da232f7af47"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6faa54d44a82a8521fe0b2b23ec4876fa17c4ef88558bf3267ea0ec1b06ccdaf · sha256:beff78847401b635… · /containers/cna/references/1
{"name":"https://github.com/getkirby/kirby/releases/tag/5.2.2","tags":["x_refsource_MISC"],"url":"https://github.com/getkirby/kirby/releases/tag/5.2.2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6faa54d44a82a8521fe0b2b23ec4876fa17c4ef88558bf3267ea0ec1b06ccdaf · sha256:beff78847401b635… · /containers/cna/references/2
{"name":"https://github.com/getkirby/kirby/security/advisories/GHSA-4j78-4xrm-cr2f","tags":["x_refsource_CONFIRM"],"url":"https://github.com/getkirby/kirby/security/advisories/GHSA-4j78-4xrm-cr2f"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6faa54d44a82a8521fe0b2b23ec4876fa17c4ef88558bf3267ea0ec1b06ccdaf · sha256:beff78847401b635… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.