CVE-2026-103475
Received Received - Intake

Yii2-Starter-Kit Debug Module Unauthorized Access Vulnerability

Vulnerability report for CVE-2026-103475, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulnCheck

Description

yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii endpoint to generate and write PHP files into the application directory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
yiisoft yii 4.2.0
yii2-starter-kit yii2-starter-kit to 4.2.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-489 The product is released with debugging code still enabled or active.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects yii2-starter-kit versions up to 4.2.0. The default development configuration sets allowedIPs to ['*'] for the Yii debug and Gii modules, making them accessible to all IP addresses. Unauthenticated remote attackers can access the debug endpoint to read sensitive data like session cookies and database queries, or use the Gii endpoint to generate and write PHP files into the application directory.

Detection Guidance

Check if the Yii debug or Gii modules are enabled in your Yii2 application configuration files. Look for files like web.php or main.php in the common/config or backend/config directories. Search for lines containing 'allowedIPs' set to ['*'] in debug or Gii module configurations.

Impact Analysis

Attackers can exploit this to read sensitive data such as session cookies and database queries via the debug endpoint. They can also generate and write PHP files through the Gii endpoint, leading to potential remote code execution and full system compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Non-compliance may result in legal penalties and reputational damage.

Mitigation Strategies

Update yii2-starter-kit to a version beyond 4.2.0. If updating is not possible, modify the configuration files to restrict allowedIPs for debug and Gii modules to specific trusted IPs only. Disable these modules in production environments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103475. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart