← Back to CVE search

CVE-2026-72698

Grav CMS

Description

Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing content editors to read sensitive configuration values. Attackers with page-content edit access can access raw configuration arrays including secrets like cache credentials by using dot notation in Twig templates, bypassing the config_denied_paths restrictions.

CVSS 6.5EPSS 0.241%Risk 0.66
View source
Published
2026-08-25 02:16:45
Affected versions
<2.0.16
Type
Web application
Last modified
2026-08-26 17:17:13
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N