PT-2026-94108 · Craft Cms · Craft Cms

·

CVE-2026-92591

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Craft CMS versions 5.0.0 through 5.10.12
Description A failure in the database connection is incorrectly interpreted as the software not being installed. This allows anonymous installer actions, such as install/validate-site, to be accessed on a production site if PHP is available but the MySQL endpoint is not. The process accepts a site name, serializes it via Site::getName(), and expands ${NAME} expressions using App::env(). An unauthenticated attacker with a valid guest session cookie and CSRF token can provide a predictable variable name, such as CRAFT SECURITY KEY, to disclose sensitive information including process environment variables, $ SERVER entries, PHP constants, database credentials, or API keys. This issue requires an independent database outage to be exploitable.
Recommendations Update Craft CMS to version 5.10.13.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92591
GHSA-HFJH-GW6X-7PV5

Affected Products

Craft Cms