CVE-2026-71415 | getkirby Kirby up to 5.5.1 REST API chunk upload handler src/Api/Upload.php processChunk Upload-Length improper authorization

SecurityVulns

A vulnerability marked as problematic has been reported in getkirby Kirby up to 5.5.1. Impacted is the function KirbyApiUpload::processChunk of the file src/Api/Upload.php of the component REST API chunk upload handler. The manipulation of the argument Upload-Length leads to improper authorization.

This vulnerability is uniquely identified as CVE-2026-71415. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More