Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and offsetexists() methods that lack field filtering. Attackers with page-edit permissions can call offsetGet() on User objects to extract hashed passwords and 2FA secrets, enabling offline password cracking and authentication bypass.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-25 02:16
Updated : 2026-08-31 20:50
NVD link : CVE-2026-76839
Mitre link : CVE-2026-76839
CVE.ORG link : CVE-2026-76839
JSON object : View
Products Affected
No product.
CWE
CWE-522
Insufficiently Protected Credentials
