THREAT OPS › Threat News › [NVD] CVE-2026-69127 — Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthenticated API users. This vulnerability aff
[NVD] CVE-2026-69127 — Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthenticated API users. This vulnerability aff
CVE-2026-69127 CVSS: None Published: 2026-08-07T19:18:53.107
Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthenticated API users. This vulnerability affects all Kirby sites that have not disabled the REST API
Indicators of compromise
- CVE-2026-69127cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-69127