PT-2026-81148 · Grav · Grav

·

CVE-2026-76839

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grav versions prior to 2.0.16
Description Sandboxed Twig templates can access sensitive User fields because the allow-listed offsetGet() and offsetexists() methods lack proper field filtering. Users with page-edit permissions can utilize the offsetGet() function on User objects to retrieve hashed passwords and 2FA secrets, which may facilitate offline password cracking and authentication bypass.
Recommendations Update Grav to version 2.0.16 or later.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76839
GHSA-3JHR-MXMX-38CX

Affected Products

Grav