CVE-2026-21896: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-21896 is an Incorrect Authorization vulnerability in Kirby CMS that allows authenticated low-privileged users to bypass configured write restrictions in the content changes API. It affects Kirby versions 5.0.0 through 5.2.1 and was disclosed on January 8, 2026, with a patch released the same day in version 5.2.2. The vulnerability only impacts sites where custom user permissions have been configured to restrict the update permission for specific roles; sites using default permissions are unaffected. It carries a CVSS v3.1 base score of 5.7 (Medium) and a CVSS v4.0 base score of 5.8 (Medium) (GitHub Advisory, Kirby Release).

Technical details

The root cause is CWE-863 (Incorrect Authorization): Kirby's API backend code in src/Api/Controller/Changes.php failed to enforce model update permissions for operations on the "changes" content version (the draft/unsaved-changes layer). The discard(), publish(), and save() methods in the Changes controller did not call $model->permissions()->can('update') before executing write operations, meaning any authenticated Panel user could invoke these API endpoints regardless of their role's configured restrictions. The fix (commit f5ce134) adds explicit permission checks at the start of each of these three methods, throwing a PermissionException when the user lacks the update permission (GitHub Advisory, Patch Commit).

Impact

A low-privileged authenticated attacker with Panel access can create, modify, or discard content change versions across arbitrary models (pages, users, files, or the site object), circumventing role-based access controls intended to prevent write operations. Concrete impacts include: injecting defamatory, spam, or malicious content (e.g., links or scripts) into pending changes that an inattentive editor with publish rights could inadvertently publish; creating editing locks that block legitimate editors from making changes; and discarding extensive unsaved editor work. There is no confidentiality impact, and the vulnerability is scoped to the vulnerable system only (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability requires the attacker to already have a valid Panel account (low privileges) and some form of user interaction (e.g., a legitimate editor publishing the tampered changes). The EPSS score is approximately 0.03%, reflecting low exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The issue was responsibly reported by Lukas Kleinschmidt (@lukaskleinschmidt) (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Kirby CMS installation running versions 5.0.0–5.2.1 where custom role permissions have been configured to disable the update permission for one or more roles.
  2. Obtain low-privileged credentials: Acquire or use an existing Panel account assigned to a restricted role (one that should not have write access to content).
  3. Authenticate to the Panel API: Log in to the Kirby Panel and obtain a valid session token or cookie.
  4. Target the Changes API endpoint: Send authenticated API requests directly to the content changes API endpoints (e.g., those handled by Changes::save(), Changes::discard(), or Changes::publish()) for arbitrary models, bypassing the Panel UI which may enforce role restrictions client-side.
  5. Inject or discard content: Use the save action to write malicious content (e.g., spam links, scripts) into the changes version of a target page or model, or use discard to delete pending editor work, or use publish to push changes directly.
  6. Social engineering (optional): Wait for or manipulate a higher-privileged editor to review and publish the tampered changes, causing malicious content to go live (GitHub Advisory, Patch Commit).

Indicators of compromise

  • Logs: Kirby Panel/API access logs showing API requests to content changes endpoints (save, discard, publish) originating from user accounts assigned to roles that should not have update permissions.
  • File System: Unexpected or unauthorized _changes/ directory entries for content models (e.g., _changes/article.txt) created or modified by low-privileged user accounts; content files containing unexpected links, scripts, or defamatory text in draft/changes versions.
  • Application Behavior: Editing locks appearing on content models without corresponding legitimate editor sessions; editors reporting lost unsaved work (indicating unauthorized discard operations); unexpected content appearing in published pages that was not authored by authorized users.

Mitigation and workarounds

Upgrade Kirby to version 5.2.2 or later, which adds explicit update permission checks to the discard(), publish(), and save() methods in the Changes controller. No configuration-based workaround is available for affected versions; patching is the only remediation. Sites that have not customized user permissions away from Kirby's defaults are not affected but should still upgrade as a best practice. Administrators should also review Panel access logs for unauthorized API calls to the content changes endpoints and audit content change versions for unexpected modifications (Kirby Release, GitHub Advisory).

Community reactions

The vulnerability was responsibly disclosed by Lukas Kleinschmidt and patched by the Kirby team on the same day it was published (January 8, 2026). The Kirby maintainers credited the reporter and noted that a future release will add more granular edit and save permissions to provide finer-grained control over write actions. No significant broader media coverage or notable community controversy has been observed beyond standard vulnerability tracking (GitHub Advisory, Kirby Release).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management