Description
Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed production site whenever PHP remains available but the configured MySQL endpoint does not. The action accepts a site name, serializes it through Site::getName(), and expands ${NAME} expressions using App::env(). An unauthenticated attacker who obtained a guest session cookie and matching CSRF token before the outage and whose session remains valid during it can submit a predictable variable name (for example Craft's conventional CRAFT_SECURITY_KEY) and receive its value, disclosing Craft secrets, process environment variables, $_SERVER entries, or PHP constants such as the security key, database credentials, or API keys. The issue requires an independently occurring database outage; the vulnerability itself provides no way to induce it. Fixed in 5.10.13.
Published: 2026-09-16
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Environment secret exposure
Action: Immediate Patch
AI Analysis

Impact

Craft CMS versions 5.0.0 through 5.10.12 erroneously treat a database connection failure as if the site is not installed, allowing anonymous installer actions to be accessed on an active production instance when PHP is still running but the MySQL endpoint is unavailable. If an attacker has a valid guest session cookie and a matching CSRF token that remain valid during the outage, they can submit a predictable variable name through the install/validate-site action. The action serializes the supplied site name and expands ${NAME} expressions using App::env(), which causes the system to reveal values of Craft‑specific environment variables or other system variables, including the security key, database credentials, or API keys. The vulnerability does not provide a method to trigger the database outage itself; it merely exploits the system’s behavior after an external outage occurs.

Affected Systems

Craft CMS product by Craft CMS. The affected releases are all releases from 5.0.0 up to and including 5.10.12. Users of any of these versions are vulnerable until a later fixed release is applied.

Risk and Exploitability

Likely attack vectors are remote web exploitation by submitting a request to the installer endpoint while an outage is happening and a guest session cookie and CSRF token are still in the attacker’s possession. The CVSS score of 8.2 indicates high severity for confidentiality and integrity. The EPSS score less than 1% suggests a low probability of exploitation at any given moment. The vulnerability is not listed in CISA KEV. Remediation requires an upgrade to 5.10.13 or later.

Generated by OpenCVE AI on September 18, 2026 at 00:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑provided fix by upgrading to Craft CMS 5.10.13 or a later release.
  • Restrict the lifetime of guest session cookies and enforce CSRF token expiration so that a guest session cannot survive a database outage, thereby reducing the exploitation window.
  • Ensure that sensitive environment variables (e.g., CRAFT_SECURITY_KEY, database credentials, API keys) are not exposed through the installer by reviewing application configuration and disabling unnecessary environment variable expansion during installation.

Generated by OpenCVE AI on September 18, 2026 at 00:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed production site whenever PHP remains available but the configured MySQL endpoint does not. The action accepts a site name, serializes it through Site::getName(), and expands ${NAME} expressions using App::env(). An unauthenticated attacker who obtained a guest session cookie and matching CSRF token before the outage and whose session remains valid during it can submit a predictable variable name (for example Craft's conventional CRAFT_SECURITY_KEY) and receive its value, disclosing Craft secrets, process environment variables, $_SERVER entries, or PHP constants such as the security key, database credentials, or API keys. The issue requires an independently occurring database outage; the vulnerability itself provides no way to induce it. Fixed in 5.10.13.
Title Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer
First Time appeared Craftcms
Craftcms craft Cms
Weaknesses CWE-636
CPEs cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
Vendors & Products Craftcms
Craftcms craft Cms
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Craftcms Craft Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T13:26:27.358Z

Reserved: 2026-09-16T13:47:49.170Z

Link: CVE-2026-92591

cve-icon Vulnrichment

Updated: 2026-09-17T13:25:21.937Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T22:18:29.873

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-92591

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:30:02Z

Weaknesses
  • CWE-636

    Not Failing Securely ('Failing Open')