CVE-2026-63092: Missing Authorization in medienbaecker kirby-modules
kirby-modules versions up to and including 5.5.7 contain an information disclosure vulnerability that allows any authenticated Kirby Panel user to retrieve the full plaintext commercial license key. This occurs because the activate dialog endpoint does not enforce an administrator check and is accessible to users with the default access.system permission. The vulnerability was fixed in a commit after version 5.5.7. The disclosed license key could be used to activate the plugin on unauthorized third-party installations.
AI Analysis
Technical Summary
The kirby-modules plugin through version 5.5.7 has an information disclosure vulnerability (CVE-2026-63092) where the activate dialog handler in lib/areas.php returns the complete commercial license key via ModulesLicense::readKey() without verifying that the requesting user is an administrator. Instead, the dialog is gated only by the access.system permission, which defaults to true for all non-admin roles. This allows any authenticated Kirby Panel user to send a GET request to the modules/activate dialog endpoint and retrieve the full plaintext license key. The vulnerability enables attackers to misuse the license key to activate the plugin on arbitrary third-party installations. The issue was fixed in a commit identified as 315417e, which is after version 5.5.7.
Potential Impact
Any authenticated user with access to the Kirby Panel, even without administrator privileges, can retrieve the full plaintext commercial license key. This key disclosure can lead to unauthorized activation of the kirby-modules plugin on other installations, potentially violating licensing terms and enabling unauthorized use of the software. There is no indication of remote code execution or system compromise beyond license key disclosure.
Mitigation Recommendations
A fix for this vulnerability is available in a commit after version 5.5.7 (commit 315417e). Users should upgrade to a version that includes this fix. Until then, restrict access to the Kirby Panel to trusted administrators only to reduce the risk of unauthorized license key disclosure. Patch status is not explicitly confirmed in a vendor advisory; therefore, check the vendor's official repository or advisory for the current remediation guidance and apply the official fix when available.
CVE-2026-63092: Missing Authorization in medienbaecker kirby-modules
Description
kirby-modules versions up to and including 5.5.7 contain an information disclosure vulnerability that allows any authenticated Kirby Panel user to retrieve the full plaintext commercial license key. This occurs because the activate dialog endpoint does not enforce an administrator check and is accessible to users with the default access.system permission. The vulnerability was fixed in a commit after version 5.5.7. The disclosed license key could be used to activate the plugin on unauthorized third-party installations.
CVSS v4.0
Score 5.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The kirby-modules plugin through version 5.5.7 has an information disclosure vulnerability (CVE-2026-63092) where the activate dialog handler in lib/areas.php returns the complete commercial license key via ModulesLicense::readKey() without verifying that the requesting user is an administrator. Instead, the dialog is gated only by the access.system permission, which defaults to true for all non-admin roles. This allows any authenticated Kirby Panel user to send a GET request to the modules/activate dialog endpoint and retrieve the full plaintext license key. The vulnerability enables attackers to misuse the license key to activate the plugin on arbitrary third-party installations. The issue was fixed in a commit identified as 315417e, which is after version 5.5.7.
Potential Impact
Any authenticated user with access to the Kirby Panel, even without administrator privileges, can retrieve the full plaintext commercial license key. This key disclosure can lead to unauthorized activation of the kirby-modules plugin on other installations, potentially violating licensing terms and enabling unauthorized use of the software. There is no indication of remote code execution or system compromise beyond license key disclosure.
Mitigation Recommendations
A fix for this vulnerability is available in a commit after version 5.5.7 (commit 315417e). Users should upgrade to a version that includes this fix. Until then, restrict access to the Kirby Panel to trusted administrators only to reduce the risk of unauthorized license key disclosure. Patch status is not explicitly confirmed in a vendor advisory; therefore, check the vendor's official repository or advisory for the current remediation guidance and apply the official fix when available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-15T15:45:44.600Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5fdfa79c2644c7f8c1b069
Added to database: 07/21/2026, 21:07:51 UTC
Last enriched: 07/30/2026, 04:22:35 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 30
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.