CVE-2026-63092
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any authenticated Kirby Panel user to retrieve the full plaintext commercial license key by sending a GET request to the modules/activate dialog endpoint. The plugin's activate dialog handler in lib/areas.php returns the complete key via ModulesLicense::readKey() without performing an administrator check, as the dialog is gated only by the access.system permission which defaults to true for all non-admin roles, enabling attackers to use the disclosed key to activate the plugin on arbitrary third-party installations.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| medienbaecker | kirby-modules | 0 <= 5.5.7 | affected |
| medienbaecker | kirby-modules | 315417e4fa9f18682e4382c9f44c04bd0913ce96 | unaffected |
Weaknesses
- CWE-862: Missing Authorization
References
- https://github.com/medienbaecker/kirby-modules/commit/315417e4fa9f18682e4382c9f44c04bd0913ce96
- https://www.vulncheck.com/advisories/kirby-modules-license-key-disclosure-via-modules-activate-dialog
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.