Sceawere

Vulnerability Detail

CVE-2026-86308UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Debug Mode Information Disclosure Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
1h ago
Vendor
light0011
Product
cms
Attack Type
Information Disclosure
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some unknown processing of the file App/Common/Conf/config.php of the component Debug Mode. The manipulation of the argument DB_DEBUG results in information disclosure. It is possible to launch the attack remotely. The exploit is now public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-07T14:16:56.120Z",
  "pubdate": "2026-09-07T14:16:56.120Z",
  "executiveSummary": "A critical information disclosure vulnerability exists in light0011 cms, specifically within the Debug Mode configuration handling. The vulnerability arises from improper management of the DB_DEBUG argument located in the App/Common/Conf/config.php file.\nThe flaw permits remote attackers to bypass security boundaries and extract sensitive configuration or environment data. This exposure occurs because the application improperly exposes diagnostic information when the debug functionality is triggered.\nAs the product utilizes a rolling release model, specific version numbers are unavailable; however, the vulnerability affects the identified code states c774dce31c6df0055568a8d5c53d964d99be199d and f72cf46f601efb2a0618c3814cc2f61380b38930.\nThe risk implication is significant as the exploit is publicly available, allowing unauthenticated remote actors to gain insight into the application's internal structure, database configurations, and potentially other sensitive metadata. Given the lack of response from the maintainers, the attack surface remains exposed, necessitating immediate manual intervention by system administrators to secure the application environment.",
  "technicalDetails": "The vulnerability is rooted in the insecure configuration management of the light0011 cms application. Specifically, the component responsible for Debug Mode in App/Common/Conf/config.php fails to sanitize or restrict access to the DB_DEBUG configuration parameter. When this parameter is improperly manipulated or accessed via an external request, the application fails to enforce appropriate access controls, leading to the leakage of sensitive internal state information.\nThe attack flow initiates when an unauthenticated remote attacker identifies the endpoint responsible for processing the configuration parameters associated with the Debug Mode. By supplying specific, crafted inputs to the DB_DEBUG argument, the attacker triggers an error handling or diagnostic routine within the framework that is configured to display verbose information. Because the application logic does not sufficiently validate the context of the request, it outputs sensitive system details that would otherwise remain hidden from external users.\nThis information disclosure is categorized as an improper sensitive information disclosure, often leading to the exposure of database connection strings, credentials, or filesystem paths, which are stored within the scope of the affected config.php file. The vulnerability is exploitable remotely over standard network protocols, requiring no prior authentication or administrative privileges to execute. Upon successful exploitation, the attacker receives a verbose response from the server containing the contents of the memory or system configuration files associated with the database connection.\nFrom a technical perspective, the vulnerability persists due to the lack of a production-ready configuration state in the code. The rolling release model has resulted in a codebase that retains development-oriented diagnostic functions in production environments. Without a robust configuration management policy or an environment-specific filter to disable debug output, the application remains susceptible to reconnaissance efforts. Post-exploitation impact includes full system reconnaissance, which serves as a precursor to more advanced attacks, such as database injection or unauthorized data exfiltration, as the adversary now possesses the necessary credentials and architectural mapping of the backend environment."
}
CVE-2026-86308: Debug Mode Information Disclosure Vulnerability (MEDIUM Severity, CVSS: 5.3) - Sceawere