Arbitrary Constructor Execution Vulnerability in DebugKit for CakePHP Applications
CVE-2026-54614
4.3MEDIUM
What is CVE-2026-54614?
The DebugKit tool for CakePHP applications has a vulnerability in its MailPreview feature prior to versions 4.10.3 and 5.2.4. This issue arises from the ability to control the 'previewName' value, leading the application to resolve a class without proper validation. If an attacker accesses DebugKit while debug mode is enabled, they can exploit this to execute arbitrary constructors from unintended classes, potentially disclosing sensitive application information. Affected users are encouraged to upgrade to the latest versions to mitigate the risk.
Affected Version(s)
debug_kit < 4.10.3 < 4.10.3
debug_kit >= 5.0.0, < 5.2.4 < 5.0.0, 5.2.4
