Kirby Content Management System User Information Disclosure Vulnerability via Content Locks

Vulnerability

A vulnerability exists in Kirby, an open-source content management system, in versions prior to 4.9.1 and 5.4.1. The issue arises from the content-locking feature, which fails to verify a user's access permissions before disclosing lock information. This feature is designed to prevent conflicting edits by multiple users by indicating who is currently editing a model. However, the system inadvertently exposes the email addresses and identifiers of users, including those with administrative privileges, to low-privilege authenticated Panel users whose roles restrict access to user information. This flaw could be exploited to enumerate admin accounts, facilitate phishing attacks, and conduct credential-stuffing attacks against the affected Kirby installation or other sites.

Impact

Exploitation of this vulnerability allows unauthorized access to the email addresses and user IDs of individuals currently editing a model in the Kirby Panel, including administrators. Such information could be used to target phishing attacks, enumerate admin accounts, and launch credential-stuffing attacks.

Remediation

Users can update to Kirby versions 4.9.1 or 5.4.1 to address this vulnerability. In these versions, the content-lock information is filtered according to the user's permissions, ensuring that only authorized users can access details about who is editing a model.

Added: Jul 17, 2026, 12:55 AM
Updated: Jul 17, 2026, 12:55 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.6
exploitability
5.0
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.