CVE-2026-21896 Details
Description
Kirby is an open-source content management system. From versions 5.0.0 to 5.2.1, Kirby is missing permission checks in the content changes API. This vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the update permission with the intent to prevent modifications to site content. This vulnerability does not affect those who have not altered the deviated from default user permissions. This issue has been patched in version 5.2.2.
A vulnerability exists in Kirby, an open-source content management system, in versions 5.0.0 prior to 5.2.1. The issue arises from missing permission checks in the content changes API, specifically affecting sites where user permissions have been customized to restrict certain roles from writing. This vulnerability allows users with Panel access to manipulate changes versions and content fields, potentially disrupting the work of other users and introducing unauthorized changes.
Update Kirby to version 5.2.2 or later, where this vulnerability has been patched. In this release, permission checks have been added to ensure that users without update permissions cannot create, edit, or discard changes versions for the respective model.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/getkirby/kirby/commit/f5ce1347b427b819bf193acf11fd0da232f7af47 | [email protected] | Patch |
| https://github.com/getkirby/kirby/releases/tag/5.2.2 | [email protected] | ProductRelease Notes |
| https://github.com/getkirby/kirby/security/advisories/GHSA-4j78-4xrm-cr2f | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| getkirby kirby | >= 5.0.0, < 5.2.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 2, 2026 | Initial Analysis | [email protected] |
| Jan 8, 2026 | New CVE Received | [email protected] |