CVE-2026-54614 affects CakePHP DebugKit's MailPreview route in versions earlier than 4.10.3 and 5.2.4. A user-controlled previewName can pass through PHP autoloading and cause unintended application classes to be instantiated without verifying that they extend DebugKit\Mailer\MailPreview. Crafted namespaced values may therefore execute available class constructors—and potentially destructor-based gadget behavior—with impacts ranging from limited information disclosure to file modification or deletion depending on the application’s installed classes.
Exploitation requires access to DebugKit with debug mode enabled, typically in development environments but potentially in publicly exposed or misconfigured production deployments; hostname checks based on local or allowlisted hosts may also be bypassable. CakePHP fixed the issue by rejecting backslashes in preview names and enforcing the expected MailPreview subclass check. Organizations should upgrade to DebugKit 4.10.3 or 5.2.4 or later, disable debug mode outside development, restrict DebugKit access, and exclude development dependencies from production deployments. The reported CVSS v3 score is 4.3 and no public exploits were known at publication.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
CakePHP published CVE-2026-54614, an unsafe class-instantiation flaw in DebugKit MailPreview that can permit arbitrary constructor execution when DebugKit is accessible. The issue was fixed in DebugKit versions 4.10.3 and 5.2.4.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcetenable.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.