{"id":"CVE-2026-63092","summary":"kirby-modules License Key Disclosure via modules/activate Dialog","details":"kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any authenticated Kirby Panel user to retrieve the full plaintext commercial license key by sending a GET request to the modules/activate dialog endpoint. The plugin's activate dialog handler in lib/areas.php returns the complete key via ModulesLicense::readKey() without performing an administrator check, as the dialog is gated only by the access.system permission which defaults to true for all non-admin roles, enabling attackers to use the disclosed key to activate the plugin on arbitrary third-party installations.","modified":"2026-07-23T04:03:08.856888543Z","published":"2026-07-21T20:50:18.823Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-862"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63092.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63092.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63092"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/kirby-modules-license-key-disclosure-via-modules-activate-dialog"},{"type":"FIX","url":"https://github.com/medienbaecker/kirby-modules/commit/315417e4fa9f18682e4382c9f44c04bd0913ce96"},{"type":"PACKAGE","url":"https://github.com/medienbaecker/kirby-modules"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/medienbaecker/kirby-modules","events":[{"introduced":"0"},{"fixed":"2663221e6cb0de95b3b26b8111db777fc57f836b"},{"fixed":"315417e4fa9f18682e4382c9f44c04bd0913ce96"}],"database_specific":{"source":["DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"5.5.7"}]}}],"versions":["5.5.7","5.5.6","5.5.5","5.5.4","5.5.3","5.5.2","5.5.1","5.5.0","5.4.0","5.3.0","5.2.1","5.2.0","5.1.1","5.1.0","5.0.2","5.0.1","5.0.0","5.0.0-rc.8","5.0.0-rc.7","5.0.0-rc.6","5.0.0-rc.5","5.0.0-rc.4","5.0.0-rc.3","5.0.0-rc.2","5.0.0-rc.1","3.0.0","2.9.3","2.9.2","2.9.1","2.9.0","2.8.4","2.8.3","2.8.2","2.8.1","2.8.0","2.7.0","2.6.0","2.5.2","2.5.1","2.5.0","2.4.1","2.4.0","2.3.1","2.3.0","2.2.3","2.2.2","2.2.1","2.2.0","2.1.1","2.1.0","2.0.1","2.0.0","0.7.0","0.6.3","0.6.2","0.6.1","0.6","0.5.1","0.5","0.4","0.3","0.2","0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63092.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}