Zuwardo-Zero

#32593of 57,454
8.7Total CVSS
Vulnerabilities · 1
PT-2026-94239
8.7
2026-09-17
Grav · Grav · CVE-2026-92916
**Name of the Vulnerable Software and Affected Versions** Grav versions 1.7.0 through 1.7.53.2 Grav versions 2.0.0 through 2.0.21 **Description** When the debugger is enabled via `system.debugger.enabled: true`, the Clockwork profiler endpoint is exposed without authentication. The `InitializeProcessor::handleDebuggerRequest()` function intercepts paths containing the '/ clockwork/' endpoint and passes them to `Debugger::debuggerRequest()`, which fails to perform user lookups, IP restrictions, or authenticator checks. This allows anonymous pagination over the stored history. By default, records may contain raw request cookies, including session cookies that allow session hijacking of authenticated administrators. Additionally, the full parsed request body is stored, leading to plaintext exposure of `data[username]` and `data[password]` because the password filter only inspects top-level keys. The system also exposes site configurations, SMTP credentials, third-party API keys, and license keys. Authorization and `X-API-Token` headers remain stored even when the censored option is enabled. In version 2.0, using the `provider: debugbar` setting does not mitigate this as the Clockwork provider is forced for requests preferring JSON responses. **Recommendations** Update Grav versions 1.7.0 through 1.7.53.2 to version 1.7.53.4. Update Grav versions 2.0.0 through 2.0.21 to version 2.0.22. Set `system.debugger.enabled` to `false`. Block access to the '/ clockwork/' endpoint at the web server or CDN level.