Arbitrary Constructor Execution Vulnerability in DebugKit for CakePHP Applications
CVE-2026-54614

4.3MEDIUM

Key Information:

Vendor

CakePHP

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-54614?

The DebugKit tool for CakePHP applications has a vulnerability in its MailPreview feature prior to versions 4.10.3 and 5.2.4. This issue arises from the ability to control the 'previewName' value, leading the application to resolve a class without proper validation. If an attacker accesses DebugKit while debug mode is enabled, they can exploit this to execute arbitrary constructors from unintended classes, potentially disclosing sensitive application information. Affected users are encouraged to upgrade to the latest versions to mitigate the risk.

Affected Version(s)

debug_kit < 4.10.3 < 4.10.3

debug_kit >= 5.0.0, < 5.2.4 < 5.0.0, 5.2.4

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.