What is CVE-2026-69127?
CVE-2026-69127 is a vulnerability in the Kirby CMS where the REST API error handler returns unsanitized PHP error messages, exposing the full filesystem path to unauthenticated API users. This affects versions prior to 4.9.5 and from 5.0.0 through 5.5.1. Users should update to the latest security release or restrict REST API access.
Azərbaycanca: CVE-2026-69127, Kirby CMS-in REST API xəta idarəçisində sanitizasiya olunmamış PHP xəta mesajları vasitəsilə autentifikasiya olunmamış API istifadəçilərinə tam fayl sistemi yolunu ifşa edən zəiflikdir. Bu, 4.9.5-dən əvvəlki və 5.0.0-5.5.1 versiyalarına təsir edir. İstifadəçilər ən son təhlükəsizlik yeniləməsinə keçməli və ya REST API girişini məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Through which component is CVE-2026-69127 exploited in Kirby CMS?
CVE-2026-69127 is exploited through unsanitized PHP error messages in Kirby CMS's REST API error handler.
Which Kirby CMS versions are affected by CVE-2026-69127?
This vulnerability affects all Kirby CMS versions prior to 4.9.5, as well as versions from 5.0.0 through 5.5.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.