Threat Advisory

CakePHP Debug Kit Flaw Lets Attackers Execute Arbitrary Code

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-54614 is a medium severity vulnerability with a CVSS score of 4.3, classified as an arbitrary constructor execution flaw type via the MailPreview feature in cakephp/debug_kit when debug mode is enabled and the hostname matches 'local' domain or is on an allowlist, affecting versions prior to 4.10.3 and from 5.0.0 up to but not including 5.2.4, enabling attackers to execute malicious code without user interaction, resulting in a business impact of potential unauthorized data access and system compromise through arbitrary code execution.

RECOMMENDATION:

We recommend you to update cakephp/debug_kit to version 4.10.3 or 5.2.4.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-54614 is a medium severity vulnerability with a CVSS score of 4.3, classified as an arbitrary constructor execution flaw type via the MailPreview feature in cakephp/debug_kit when debug mode is enabled and the hostname matches 'local' domain or is on an allowlist, affecting versions prior to 4.10.3 and from 5.0.0 up to but not including 5.2.4, enabling attackers to execute malicious code without user interaction, resulting in a business impact of potential unauthorized data access and system compromise through arbitrary code execution.

RECOMMENDATION:

We recommend you to update cakephp/debug_kit to version 4.10.3 or 5.2.4.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu