PT-2026-81141 · Grav Cms · Grav Cms

·

CVE-2026-72698

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grav CMS versions prior to 2.0.16
Description Sandboxed Twig renders fail to filter system, site, and theme configuration arrays. This allows users with page-content edit access to read sensitive configuration values, such as cache credentials, by using dot notation in Twig templates. This technique bypasses the config denied paths restrictions.
Recommendations Update Grav CMS to version 2.0.16 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72698
GHSA-P597-CRQC-M349

Affected Products

Grav Cms