CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-54003

Critical · CVSS 9.1

getkirby/cms — IP spoofing via reverse proxy headers leading to unauthorized Panel installation and admin user creation

CVSS
9.1
nvd
EPSS
0.55%
42th pct
KEV
No
Class
oss containerizable
CWE-454

Description

Kirby is an open-source content management system. Prior to 4.9.4 and from 5.4.4, Kirby sites with no configured user accounts that run on publicly accessible servers behind a reverse proxy setting the Forwarded, X-Client-IP, or X-Real-IP request header could allow remote attackers to install the Panel and create the first admin user because local-IP checks trusted those headers incorrectly. This issue is fixed in versions 4.9.4 and 5.4.4.

Search profile — drives PoC discovery

Symbols ForwardedX-Client-IPX-Real-IPlocal-IP checksPanelfirst admin userreverse proxygetkirby/kirby1c7fee90e49153cf9ca4a6ec17481d25fbedc48d3423f66c01dbc0455862e23ee699d2aa469f323466a3a14bf0892d320723ba766cd5f1d33a51d15bab992dc149610b90e337c2955ab6ccb7f72ffb3a
Keywords CVE-2026-54003Kirby CMSKirby Panel install bypassreverse proxy IP spoofingX-Client-IP X-Real-IP KirbyForwarded header Kirbygetkirby cms admin user creationCWE-454 KirbyKirby no user accounts exploitKirby 4.9.4 5.4.4 patch
Versions: < 4.9.4 and >= 5.0.0, < 5.4.4

Affected packages

Packagist getkirby/cms 0 → 4.9.4
Packagist getkirby/cms 5.0.0-alpha.1 → 5.4.4

References

Status: enriched · ingested 2026-07-10T18:00:26.000Z · profiled 2026-07-10T18:30:26.000Z