← العودة للجدول
CVE-2026-75594
CVE-2026-75594 — Kirby: Access to image files and limited access to JSON files outside of the sit
📅 2026-09-01
🟠 High 🔥 No GHSA Vulnerability Web

📋 الوصف الكامل

### TL;DR This vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes (`%2f`), such as nginx, PHP's built-in server or Apache setups that have the option `AllowEncodedSlashes` enabled. It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail

💻 الأنظمة المتأثرة

Apache HTTP Server | Nginx

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-75594

📡 المصدر

GHSA

✅ الحلول والتخفيف

Update to v4.9.5

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←