SCA: security update for getkirby/cms (GHSA-39vq-49qm-r2mc)

medium Tenable Self-Hosted Container Security Plugin ID 442391

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the content-
locking feature returned lock information without checking the requesting user's access permissions.
Kirby's Panel includes a content-locking feature that records which user currently has a model open for
editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity
in the Panel UI so other users know who to contact. Internally, the locking user's email address and
identifier are included in every Panel view payload and in error responses returned when a user attempts
to edit a model that is currently locked by another user. This allowed a low-privilege authenticated Panel
user, whose role was configured with users.access: false or users.list: false, to learn the email address
and identifier of any user who currently had a model open for editing in the Panel, including
administrators and other higher-privilege users. Content locks are active for a configurable window (10
minutes by default). The email address can allow admin account enumeration, target phishing, and feed
credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be
cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated
means. This issue has been fixed in versions 4.9.1 and 5.4.1. (CVE-2026-45334)

Solution

Update the getkirby/cms library and its related packages to version 4.9.1 or later.

See Also

https://github.com/advisories/GHSA-39vq-49qm-r2mc

Plugin Details

Severity: Medium

ID: 442391

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 5/27/2026

Updated: 7/20/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Medium

CVSS v4

Risk Factor: Medium

Base Score: 5.3

Threat Score: 1.3

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-45334

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/27/2026

Vulnerability Publication Date: 5/27/2026

Reference Information

CVE: CVE-2026-45334

cwe: CWE-862