CVE-2026-69127
Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthenticated API users. This vulnerability affects all Kirby sites that have not disabled the REST API with the 'api' => false option. This issue is fixed in versions 4.9.5 and 5.5.2.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.29%
- CWE
- CWE-497
- Published
- 2026-08-07
- Last modified
- 2026-08-11
Affected products
- getkirby kirby
- getkirby kirby
Weakness type
Related vulnerabilities
- CVE-2026-61911 — An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An...
- CVE-2026-81394 — Microsoft Excel Information Disclosure Vulnerability
- CVE-2026-81387 — Microsoft Excel Information Disclosure Vulnerability
- CVE-2026-69315 — Windows License Manager Information Disclosure Vulnerability
- CVE-2026-68842 — Windows MIDI Service Module Information Disclosure Vulnerability
- CVE-2026-71330 — Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
- CVE-2026-69832 — Win32k Information Disclosure Vulnerability
- CVE-2026-69723 — Windows Kernel Information Disclosure Vulnerability