Junglewise Threat Intelligence

CVE-2026-86308: light0011 CMS information disclosure in debug mode

CVE-2026-86308 · Severity: medium · CVSS 5.3 · Published 2026-09-07

Technologies: Light0011 CMS.

Executive brief

light0011 is a news content management system built on ThinkPHP. The application permanently enables debug mode and database debugging in production, causing exceptions and errors to return detailed information including framework paths, database structure, line numbers, and call stacks to remote users. This information disclosure helps attackers map the application's internal architecture and identify additional vulnerabilities to exploit.

Technical details

The vulnerability is an information disclosure flaw caused by enabling APP_DEBUG=True in index.php and DB_DEBUG=True in App/Common/Conf/config.php. The vulnerable component is the debug mode configuration in App/Common/Conf/config.php, specifically the DB_DEBUG parameter. The attack requires network access to the application with no authentication needed; an attacker can trigger the information disclosure by invoking endpoints that cause exceptions (such as the upload action in UserController). When exceptions occur, the application returns detailed stack traces, file paths, line numbers, and version information to remote clients instead of generic error messages. This reveals the application's internal structure, ThinkPHP framework details, and database configuration, significantly reducing the reconnaissance effort needed for follow-up attacks. No patch has been released as the project uses rolling releases and the maintainers have not responded to the issue report.

Affected products

  • light0011 CMS commit f72cf46f601efb2a0618c3814cc2f61380b38930 and related rolling releases

Timeline

  • 2026-07-18: disclosed: Issue #10 opened on GitHub
  • 2026-09-07: advisory: CVE-2026-86308 published

References