Environment Secrets Exposure in Craft CMS by Pixel & Tonic
CVE-2026-92591

8.2HIGH

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92591?

Craft CMS versions 5.0.0 through 5.10.12 contain a flaw that misinterprets database connection failures, mistakenly assuming that Craft is uninstalled. This permits unauthorized installation actions, such as install/validate-site, on a functioning production site when PHP is operational while the designated MySQL endpoint fails. An unauthenticated attacker with a valid guest session cookie can exploit this flaw by sending a predetermined variable name to retrieve sensitive information, potentially disclosing critical secrets such as security keys and database credentials. The issue requires an independent database outage to occur, and the vulnerability itself does not cause the outage.

Affected Version(s)

cms 5.0.0 < 5.10.13

cms 5.10.13

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Crypto-Cat
.