THREAT OPS › Threat News › [GHSA] GHSA-67mx-6wf2-92xp (high) — Kirby: File upload permissions are not checked during processing of chunk data
[GHSA] GHSA-67mx-6wf2-92xp (high) — Kirby: File upload permissions are not checked during processing of chunk data
GHSA-67mx-6wf2-92xp Severity: high CVE: CVE-2026-71415
Kirby: File upload permissions are not checked during processing of chunk data
### TL;DR
This vulnerability affects all Kirby sites where users of a particular role have access to the REST API (`access.panel` permission is enabled) but no permission to upload any kind of file (`files.create`, `files.replace` and `user/users.update` permissi
Indicators of compromise
- CVE-2026-71415cve
Original source: https://github.com/advisories/GHSA-67mx-6wf2-92xp