{"id":"CVE-2026-71415","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-71415","summary":"Kirby is an open-source content management system. From 5.0.0 until 5.5.2, Kirby's REST API chunk upload handler in src/Api/Upload.php did not run the relevant upload authorization…","details":"Kirby is an open-source content management system. From 5.0.0 until 5.5.2, Kirby's REST API chunk upload handler in src/Api/Upload.php did not run the relevant upload authorization preflight in Kirby\\Api\\Upload::process() before Kirby\\Api\\Upload::processChunk() persisted chunk data. An authenticated user with the access.panel permission enabled but with files.create, files.replace, and user/users.update permissions disabled could submit requests with an Upload-Length header and leave unfinished chunks in site/cache/.uploads for 24 hours. Repeating this process could consume attacker-controlled temporary storage, prevent other users from uploading files, or prevent site logic from storing data, although final permission checks still prevented unauthorized files from reaching the content or site/accounts directories. This issue is fixed in version 5.5.2.","published":"2026-08-31T21:17:48.057","modified":"2026-08-31T21:17:48.057","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/getkirby/kirby/commit/37e206f3ed40ad3fab2e47e055ccb19e9c207dab","label":"getkirby/kirby@37e206f"},"references":[{"type":"WEB","url":"https://github.com/getkirby/kirby/commit/37e206f3ed40ad3fab2e47e055ccb19e9c207dab"},{"type":"WEB","url":"https://github.com/getkirby/kirby/pull/8296"},{"type":"WEB","url":"https://github.com/getkirby/kirby/releases/tag/5.5.2"},{"type":"WEB","url":"https://github.com/getkirby/kirby/security/advisories/GHSA-67mx-6wf2-92xp"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-31T21:17:48.057"}}