CVE-2026-54003EPSS p53.2%
CVE-2026-54003CVE-2026-54003
Description
Kirby is an open-source content management system. Prior to 4.9.4 and from 5.4.4, Kirby sites with no configured user accounts that run on publicly accessible servers behind a reverse proxy setting the Forwarded, X-Client-IP, or X-Real-IP request header could allow remote attackers to install the Panel and create the first admin user because local-IP checks trusted those headers incorrectly. This issue is fixed in versions 4.9.4 and 5.4.4.
Scoring
| EPSS | 0.74% probability of exploitation · percentile 53.2% · 2026-10-06T12:00:23Z |
| Last modified | 2026-07-10 |