PT-2026-94239 · Grav · Grav

·

CVE-2026-92916

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grav versions 1.7.0 through 1.7.53.2 Grav versions 2.0.0 through 2.0.21
Description When the debugger is enabled via system.debugger.enabled: true, the Clockwork profiler endpoint is exposed without authentication. The InitializeProcessor::handleDebuggerRequest() function intercepts paths containing the '/ clockwork/' endpoint and passes them to Debugger::debuggerRequest(), which fails to perform user lookups, IP restrictions, or authenticator checks. This allows anonymous pagination over the stored history. By default, records may contain raw request cookies, including session cookies that allow session hijacking of authenticated administrators. Additionally, the full parsed request body is stored, leading to plaintext exposure of data[username] and data[password] because the password filter only inspects top-level keys. The system also exposes site configurations, SMTP credentials, third-party API keys, and license keys. Authorization and X-API-Token headers remain stored even when the censored option is enabled. In version 2.0, using the provider: debugbar setting does not mitigate this as the Clockwork provider is forced for requests preferring JSON responses.
Recommendations Update Grav versions 1.7.0 through 1.7.53.2 to version 1.7.53.4. Update Grav versions 2.0.0 through 2.0.21 to version 2.0.22. Set system.debugger.enabled to false. Block access to the '/ clockwork/' endpoint at the web server or CDN level.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92916
GHSA-Q3FF-CJ6V-RR5G

Affected Products

Grav