Environment Secrets Exposure in Craft CMS by Pixel & Tonic
CVE-2026-92591
8.2HIGH
What is CVE-2026-92591?
Craft CMS versions 5.0.0 through 5.10.12 contain a flaw that misinterprets database connection failures, mistakenly assuming that Craft is uninstalled. This permits unauthorized installation actions, such as install/validate-site, on a functioning production site when PHP is operational while the designated MySQL endpoint fails. An unauthenticated attacker with a valid guest session cookie can exploit this flaw by sending a predetermined variable name to retrieve sensitive information, potentially disclosing critical secrets such as security keys and database credentials. The issue requires an independent database outage to occur, and the vulnerability itself does not cause the outage.
Affected Version(s)
cms 5.0.0 < 5.10.13
cms 5.10.13
