PT-2026-81149 · Grav · Grav

·

CVE-2026-76846

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grav versions prior to 2.0.16
Description An incomplete default denylist in the Twig sandbox configuration allows users with page-edit permissions to access system configuration secrets. When config access is enabled, an attacker can use the config.get() or config.toArray() functions within Twig templates to retrieve sensitive information, such as the system.cache.redis.password variable.
Recommendations Update Grav to version 2.0.16 or later.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76846
GHSA-XJW5-Q542-3VMR

Affected Products

Grav