<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T16:59:21.039675+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-335486</id>
    <title>EUVD-2026-335486</title>
    <updated>2026-10-06T16:59:21.090640+00:00</updated>
    <content>EUVD-2026-335486</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-335486"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54003</id>
    <title>fkie_cve-2026-54003</title>
    <updated>2026-10-06T16:59:21.090680+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Kirby is an open-source content management system. Prior to 4.9.4 and from 5.4.4, Kirby sites with no configured user accounts that run on publicly accessible servers behind a reverse proxy setting the Forwarded, X-Client-IP, or X-Real-IP request header could allow remote attackers to install the Panel and create the first admin user because local-IP checks trusted those headers incorrectly. This issue is fixed in versions 4.9.4 and 5.4.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-whxw-24jc-cwmv</id>
    <title>GHSA-whxw-24jc-cwmv — Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header</title>
    <updated>2026-10-06T16:59:21.090714+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: getkirby/cms</p>
<p>### TL;DR</p>
<p>This vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the `Forwarded: for=...`, `X-Client-IP`, or `X-Real-IP` request header.</p>
<p>It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses.</p>
<p>**This vulnerability is of critical severity for affected sites.**</p>
<p>Your site is *not* affected if any of the following apply:</p>
<p>- An admin account has already been configured
- The Panel and API are disabled
- The site is not running behind a reverse proxy
- The reverse proxy sets the `X-Forwarded-For` or `Client-IP` header instead of the affected ones.</p>
<p>----</p>
<p>### Introduction</p>
<p>External Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication.</p>
<p>This can give untrusted actors access to the system or let them control its behavior.</p>
<p>### Affected components</p>
<p>The Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created.</p>
<p>To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-whxw-24jc-cwmv"/>
  </entry>
</feed>
