CVE-2026-69127 is an information-disclosure vulnerability affecting every Kirby CMS site running with the REST API enabled — which is the default configuration, unless an operator has explicitly set 'api' => false.
What the vulnerability does
Per Kirby’s own GitHub Security Advisory, the REST API at /api returns JSON for every request, including a special error handler that converts internal errors to JSON. In production (with the debug option disabled, as it should be), that handler is supposed to omit sensitive detail. The advisory states this sanitization was missing for a class of internal errors: some PHP errors that occur while processing a request carry the full source filesystem path of the Kirby installation inside the error message itself, and the API returned that message unsanitized — to any caller, including unauthenticated ones.
Kirby’s own advisory names the specific downstream risk: the exposed filesystem path “could be used to guess the default content.salt” — a secret value Kirby derives partly from installation-specific data — “or prepare specialized attacks.” It’s not a direct compromise on its own, but it removes a piece of information an attacker would otherwise have to guess or brute-force.
Fix
Patched in Kirby 4.9.5 and 5.5.2, per the advisory. The fix scopes full error-message exposure to exceptions in Kirby’s own Kirby\Exception namespace; all other errors (including raw PHP errors) now return a generic message outside debug mode, and even in debug mode, paths are disguised to show only the portion relative to the Kirby installation rather than the full absolute path.
Confidence
This traces directly to Kirby’s own GitHub Security Advisory with a clear technical description, root cause, and named researcher credit (Peter Levashov) — confidence is high, despite the CVSS field showing 0 in our ingested data (unscored, not zero-severity).
Why this matters
Information-disclosure bugs are easy to underrate because they don’t directly grant access. But a filesystem path leaked from an unauthenticated API endpoint is exactly the kind of low-cost reconnaissance step that narrows a subsequent attack — here, specifically toward guessing a cryptographic salt the application relies on. Any Kirby site running the REST API in its default configuration should update to 4.9.5 or 5.5.2 rather than treating this as a low-priority disclosure.
Frequently Asked Questions
What is CVE-2026-69127?
An information-disclosure vulnerability in Kirby CMS’s REST API, where unsanitized error messages could leak the full server filesystem path, aiding an attacker trying to guess the content.salt secret.
Which version fixes CVE-2026-69127? Kirby 4.9.5 or 5.5.2, and any later release.
Is CVE-2026-69127 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.
Data sourced from Kirby’s own GitHub Security Advisory, aggregated September 2026. See more vulnerability intelligence.