CVE-2026-54614
DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feature in src/Controller/MailPreviewController.php accepts a route-controlled previewName value in findPreview and passes the resolved class from App::className() to constructor execution without rejecting namespace separators or verifying that the class extends DebugKit\Mailer\MailPreview. An attacker able to access DebugKit while debug mode is enabled and the request hostname is local or allowlisted can select an unintended application class through the mail-preview preview route, resulting in arbitrary constructor execution and limited disclosure of application information. This issue is fixed in versions 4.10.3 and 5.2.4.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.31%
- CWE
- CWE-470
- Published
- 2026-08-26
- Last modified
- 2026-08-29
Affected products
- cakephp debug_kit
- cakephp debug_kit
Weakness type
Related vulnerabilities
- CVE-2026-79987 — Low-privilege RCE through element-search eager loading
- CVE-2026-41871 — Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)
- CVE-2026-41870 — Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)
- CVE-2026-58400 — GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formatter
- CVE-2026-19032 — jackson-databind resolves attacker-controlled URI schemes when deserializing java.nio.file.Path
- CVE-2026-55559 — Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance)
- CVE-2026-82078 — PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector
- CVE-2026-79784 — Vocos through 0.1.0 Arbitrary Code Execution via Unrestricted class_path in Model Configuration