External risk intelligence

Yii2-Starter-Kit Module Exposure Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-103475

The vulnerability affects a web application framework starter kit. By default, it enables debug and code generation modules accessible to any IP address. While intended for development, such applications are commonly deployed or exposed on web servers, making the management and debugging interfaces reachable from the internet if the default configuration is not restricted during deployment.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability in a web application starter kit that, by default, exposes debugging and code generation tools to any internet connection. This could allow unauthenticated attackers to access sensitive information or even inject malicious code into applications, posing a significant risk if not properly secured. The primary concern is confirming if this technology is in use and if its default, insecure development configurations have been unintentionally deployed.

  • Debug tools are openly accessible online.
  • Critical access allows data exposure or code injection.
  • Verify usage and secure development configurations.

Attack Path

How an attacker could exploit the issue

An attacker can reach the vulnerable components of this application through the internet without any authentication. If they access the debug module, they can steal sensitive information like session cookies and database queries. Alternatively, they can use the Gii module to create and upload PHP files, which could allow them to execute arbitrary code on the server.

  • No authentication required for access.
  • Access to debug or Gii modules.
  • Sensitive data exposure or arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could expose sensitive system and user data when the Yii debug and Gii modules are left in their default development configuration and are accessible over a network. Attackers could potentially view session cookies and database queries, or even write new PHP files to the application directory.

  • Sensitive application data and session cookies.
  • Unauthenticated network access to vulnerable modules.
  • Unauthorized file creation and data exposure.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability exposes sensitive application modules to unauthenticated remote attackers, with potential impact including data theft and unauthorized code execution. Real-world ownership likely falls to application or platform teams responsible for the Yii2-starter-kit deployment, with initial triage involving infrastructure and security teams to identify affected instances, assess business criticality and exposure, and coordinate with application owners for remediation planning.

  • Application or Platform teams own remediation.
  • Verify reachability and business criticality.
  • Plan remediation based on confirmed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is yii2-starter-kit?

Yii2-starter-kit is a foundational template built on the Yii2 PHP framework, designed to help developers quickly set up web applications with common features like user management and database integration. It includes powerful utility modules such as Gii, which automates code generation, and a debug toolbar for troubleshooting. While these tools significantly accelerate the development lifecycle, they are intended for local environments and provide administrative control over the application's core functionality.

What is the vulnerability in CVE-2026-103475?

This vulnerability is classified as CWE-489: Authentication Bypass by Assumed-Immutable Configuration. The software ships with a default configuration that enables the debug and Gii modules for all IP addresses. Because these powerful interfaces lack authentication, anyone who can reach the application's network address can access sensitive logs or inject custom code. Essentially, the software assumes the environment is safe, unintentionally bypassing security controls.

How does an attacker trigger this vulnerability?

An attacker triggers this by simply navigating to the specific URL paths associated with the debug or Gii modules in a web browser. No special permissions, login credentials, or complex exploit chains are required. This issue is only present when the default configuration, which sets allowedIPs to a wildcard value, remains unchanged. If a developer explicitly restricts these modules to a specific, trusted IP address or disables them before deployment, the bug cannot be triggered.

Do I need to worry if my application is internal?

According to Halo Surface Signal, this vulnerability is categorized as external because the modules are reachable over a network. While external-facing servers are at immediate, high risk, internal applications are also vulnerable if they are accessible to anyone on the corporate network. If the application is hosted in a shared environment where other users or compromised devices can reach the web server, the lack of authentication means your data and server integrity remain at risk.

How should I respond if I am using this software?

Your first step is to verify if your production deployment is currently running with the default development configuration. You should immediately restrict the debug and Gii modules to trusted IP addresses in your configuration files or disable them entirely if they are not needed. Coordinate with your application or platform teams to audit all instances of yii2-starter-kit, ensure these management endpoints are not exposed to untrusted networks, and confirm that access controls are properly implemented.

References