CVE-2026-54004
MEDIUMKirby: Access to files of top-level drafts is not protected by permissions
Title source: cnaDescription
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enabled could redirect unauthenticated clean file URL requests for files stored in top-level draft pages to physical media URLs without checking page access permissions or preview tokens, leading to disclosure of draft file contents. This issue is fixed in versions 4.9.4 and 5.4.4.
References (5)
Core 5
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/getkirby/kirby/security/advisories/GHSA-89cp-7p28-jffg
X_Refsource_Misc x_refsource_misc
https://github.com/getkirby/kirby/commit/5b9a0ed587575e39156d37fa42ca7f6c73e121f7
X_Refsource_Misc x_refsource_misc
https://github.com/getkirby/kirby/commit/bc721080cd8dd4dcb7fc20b3fd0460ee8d0603b0
X_Refsource_Misc x_refsource_misc
https://github.com/getkirby/kirby/releases/tag/4.9.4
X_Refsource_Misc x_refsource_misc
https://github.com/getkirby/kirby/releases/tag/5.4.4
Scores
CVSS v4
6.3
EPSS
0.0031
EPSS Percentile
23.6%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (2)
getkirby/kirby
< 4.9.4
getkirby/kirby
>= 5.0.0, < 5.4.4
Published
Jul 09, 2026
Tracked Since
Jul 10, 2026