Логотип exploitDog
bind:CVE-2026-21896
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-21896

Количество 2

Количество 2

nvd логотип

CVE-2026-21896

около 1 месяца назад

Kirby is an open-source content management system. From versions 5.0.0 to 5.2.1, Kirby is missing permission checks in the content changes API. This vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the update permission with the intent to prevent modifications to site content. This vulnerability does not affect those who have not altered the deviated from default user permissions. This issue has been patched in version 5.2.2.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-4j78-4xrm-cr2f

около 1 месяца назад

Kirby is missing permission checks in the content changes API

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-21896

Kirby is an open-source content management system. From versions 5.0.0 to 5.2.1, Kirby is missing permission checks in the content changes API. This vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the update permission with the intent to prevent modifications to site content. This vulnerability does not affect those who have not altered the deviated from default user permissions. This issue has been patched in version 5.2.2.

CVSS3: 5.7
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4j78-4xrm-cr2f

Kirby is missing permission checks in the content changes API

0%
Низкий
около 1 месяца назад

Уязвимостей на страницу