CVE-2026-44177
getkirby kirby
Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correctly validate the provided user ID, resulting in a path traversal vulnerability. Version 5.3.0 introduced a performance improvement to the Users collection that loaded user objects lazily when first needed. Users were queried by their ID, which was then used to locate the corresponding account directory under site/accounts. This affected the authentication API (accessible to unauthenticated requests), the users API (accessible only to authenticated users), and any other plac...
- CVSS
- 8.8
- EPSS
- 0.45% 37.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.17