Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.2%top 94%

CVE-2026-63092: Missing Authorization in medienbaecker kirby-modules

0
Medium
VulnerabilityCVE-2026-63092cvecve-2026-63092
Published: 07/21/2026 (07/21/2026, 20:50:18 UTC)
Source: CVE Database V5
Vendor/Project: medienbaecker
Product: kirby-modules

Description

kirby-modules versions up to and including 5.5.7 contain an information disclosure vulnerability that allows any authenticated Kirby Panel user to retrieve the full plaintext commercial license key. This occurs because the activate dialog endpoint does not enforce an administrator check and is accessible to users with the default access.system permission. The vulnerability was fixed in a commit after version 5.5.7. The disclosed license key could be used to activate the plugin on unauthorized third-party installations.

CVSS v4.0

Score 5.3medium

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
Low
Vuln. Integrity
None
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected software

GitHub Actionsmore threats →cve
kirby-modules
pkg:github/kirby-modules
Affected versions
<=5.5.7

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 04:22:35 UTC

Technical Analysis

The kirby-modules plugin through version 5.5.7 has an information disclosure vulnerability (CVE-2026-63092) where the activate dialog handler in lib/areas.php returns the complete commercial license key via ModulesLicense::readKey() without verifying that the requesting user is an administrator. Instead, the dialog is gated only by the access.system permission, which defaults to true for all non-admin roles. This allows any authenticated Kirby Panel user to send a GET request to the modules/activate dialog endpoint and retrieve the full plaintext license key. The vulnerability enables attackers to misuse the license key to activate the plugin on arbitrary third-party installations. The issue was fixed in a commit identified as 315417e, which is after version 5.5.7.

Potential Impact

Any authenticated user with access to the Kirby Panel, even without administrator privileges, can retrieve the full plaintext commercial license key. This key disclosure can lead to unauthorized activation of the kirby-modules plugin on other installations, potentially violating licensing terms and enabling unauthorized use of the software. There is no indication of remote code execution or system compromise beyond license key disclosure.

Mitigation Recommendations

A fix for this vulnerability is available in a commit after version 5.5.7 (commit 315417e). Users should upgrade to a version that includes this fix. Until then, restrict access to the Kirby Panel to trusted administrators only to reduce the risk of unauthorized license key disclosure. Patch status is not explicitly confirmed in a vendor advisory; therefore, check the vendor's official repository or advisory for the current remediation guidance and apply the official fix when available.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-07-15T15:45:44.600Z
Cvss Version
4.0
State
PUBLISHED
Remediation Level
null

Threat ID: 6a5fdfa79c2644c7f8c1b069

Added to database: 07/21/2026, 21:07:51 UTC

Last enriched: 07/30/2026, 04:22:35 UTC

Last updated: 07/31/2026, 19:23:00 UTC

Views: 30

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses