PT-2026-96323 · Dancer2 · Dancer2
CVE-2026-93709
·
Published
2026-09-22
·
Updated
2026-09-29
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Dancer2 versions prior to 2.2.0
Description
The AutoPage handler serves a layout as a page when an equivalent spelling of its path bypasses the guard. This occurs because the handler compares the request path against the layout directory name as text, whereas the subsequent lookup canonicalises the path. Consequently, a doubled slash, a dot segment, a percent-encoded slash, or different capitalization on case-insensitive filesystems can bypass the guard. This issue is only present when the
auto page feature is enabled, as it is disabled by default. This can lead to the disclosure of application layouts other than the public layout.Recommendations
Update to version 2.2.0 or later.
As a temporary mitigation, disable the
auto page handler.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dancer2