CVE-2026-54003CWE-454

Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header

Critical · published July 9, 2026

CVSS v4.0
9.1
EPSS
1%
Percentile
52.4
In the wild
Unconfirmed
What it is

Kirby is an open-source content management system. Prior to 4.9.4 and from 5.4.4, Kirby sites with no configured user accounts that run on publicly accessible servers behind a reverse proxy setting the Forwarded, X-Client-IP, or X-Real-IP request header could allow remote attackers to install the Panel and create the first admin user because local-IP checks trusted those headers incorrectly. This issue is fixed in versions 4.9.4 and 5.4.4.

The record
Technical detail
CVSS v4.0
9.1 · CRITICAL
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS
0.00743 · 52.4th percentile
Weakness
CWE-454 · External Initialization of Trusted Variables or Data Stores
Published
2026-07-09T18:36Z
EPSS history
Timeline
  • 09 JUL 18:36Z
    Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
    cvelistv5