What is CVE-2026-63092?
CVE-2026-63092 is an information disclosure vulnerability in the kirby-modules plugin up to version 5.5.7, allowing any authenticated Kirby Panel user to retrieve the full plaintext commercial license key by sending a GET request to the modules/activate endpoint. It is fixed in commit 315417e and upgrading is strongly recommended.
Azərbaycanca: CVE-2026-63092, kirby-modules plaginində 5.5.7 versiyasına qədər mövcud olan informasiya sızması zəifliyidir. Bu zəiflik autentifikasiya olunmuş istənilən Kirby Panel istifadəçisinə `/modules/activate` endpoint-ə GET sorğusu göndərərək tam kommersiya lisenziya açarını əldə etməyə imkan verir. Problemi aradan qaldırmaq üçün `315417e` commiti ilə yenilənmiş versiyaya keçmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What level of permissions does an attacker need to exploit CVE-2026-63092?
The attacker must be any authenticated Kirby Panel user.
What action is recommended to remediate CVE-2026-63092?
Upgrading to the version containing commit 315417e is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.