CVE-2026-54005
HIGHKirby: `pages.access` permission is not checked in the `site/find` REST API route
Title source: cnaDescription
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites where a role has the pages.access permission disabled allowed authenticated users who know or guess page IDs or UUIDs to retrieve page information, including full content and metadata, for arbitrary published pages through the /api/site/find route without authorization to access those pages. This issue is fixed in versions 4.9.4 and 5.4.4.
References (5)
Core 5
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/getkirby/kirby/security/advisories/GHSA-r3w8-2c5r-h9j9
X_Refsource_Misc x_refsource_misc
https://github.com/getkirby/kirby/commit/a16dbd4329293c2c4b9a375d2badcb27c6337004
X_Refsource_Misc x_refsource_misc
https://github.com/getkirby/kirby/commit/b22d0b64b6478ce6871dc7ec3368d7afaf078688
X_Refsource_Misc x_refsource_misc
https://github.com/getkirby/kirby/releases/tag/4.9.4
X_Refsource_Misc x_refsource_misc
https://github.com/getkirby/kirby/releases/tag/5.4.4
Scores
CVSS v4
7.1
EPSS
0.0027
EPSS Percentile
18.9%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (2)
getkirby/kirby
< 4.9.4
getkirby/kirby
>= 5.0.0, < 5.4.4
Published
Jul 09, 2026
Tracked Since
Jul 10, 2026