---
id: CVE-2026-86308
title: >-
  A vulnerability was detected in light0011 cms
  c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930
summary: >-
  A vulnerability was detected in light0011 cms
  c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930.
  This issue affects some unknown processing of the file
  App/Common/Conf/config.php of the component Debug Mod…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
  - CWE-284
  - CWE-215
vendor: light0011
product: cms
affected:
  - cms c774dce31c6df0055568a8d5c53d964d99be199d
  - cms f72cf46f601efb2a0618c3814cc2f61380b38930
published: '2026-09-07'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T15:17:17.033'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86308'
references:
  - url: 'https://github.com/light0011/cms/'
    label: cna@vuldb.com
  - url: 'https://github.com/light0011/cms/issues/10'
    label: cna@vuldb.com
  - url: 'https://github.com/light0011/cms/issues/17'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-86308'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/894870'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399481'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399481/cti'
    label: cna@vuldb.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-86308.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-86308'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2529462'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-86308'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86308'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-09T14:33:53.798649Z'
epss: 0.00315
epssPercentile: 0.24614
ingestedAt: '2026-09-08T15:33:26.978Z'
---

## Overview

A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some unknown processing of the file App/Common/Conf/config.php of the component Debug Mode. The manipulation of the argument DB_DEBUG results in information disclosure. It is possible to launch the attack remotely. The exploit is now public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · updated 2026-09-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-86308.json)
