THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-69127 — Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthenticated API users. This vulnerability aff

[NVD] CVE-2026-69127 — Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthenticated API users. This vulnerability aff

lownvdPublished 2026-08-07

CVE-2026-69127 CVSS: None Published: 2026-08-07T19:18:53.107

Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthenticated API users. This vulnerability affects all Kirby sites that have not disabled the REST API

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-69127