← العودة للجدول
CVE-2026-71415
CVE-2026-71415 — Kirby: File upload permissions are not checked during processing of chunk data
📅 2026-09-01
🟠 High 🔥 No GHSA Exploit Open Source

📋 الوصف الكامل

### TL;DR This vulnerability affects all Kirby sites where users of a particular role have access to the REST API (`access.panel` permission is enabled) but no permission to upload any kind of file (`files.create`, `files.replace` and `user/users.update` permissions are all disabled). It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user wit

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-71415

📡 المصدر

GHSA

✅ الحلول والتخفيف

Update to v5.5.2

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←