Impact
Kirby CMS versions earlier than 4.9.1 and 5.4.1 mishandle the content‑locking feature. When a user’s role lacks users.access or users.list permissions, the system still returns lock data that includes the editing user's email address and internal ID for every Panel view and lock‑related error. This disclosure allows a low‑privilege authenticated Panel user to learn the identities of any user currently editing a model, including administrators.
Affected Systems
The flaw is present in all releases of the open‑source Kirby content management system prior to version 4.9.1 for the 4.x line and before 5.4.1 for the 5.x line. Any site running those older versions, regardless of the number of users, is potentially vulnerable. The content‑locking feature is active by default and remains valid for a configurable ten‑minute window.
Risk and Exploitability
The CVSS base score of 5.3 classifies the vulnerability as moderate. The EPSS score is below 1 %, indicating a low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. An attacker only needs a low‑privilege authenticated Panel account with a role that disables users.access or users.list; no privilege escalation or remote code execution is required. The attack vector is via the web interface and does not depend on network segmentation, making it readily available to any valid user.
OpenCVE Enrichment
Github GHSA