Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to system configuration secrets. Attackers with page-edit permission can use config.get() or config.toArray() in Twig templates to retrieve sensitive values like system.cache.redis.password when config_access is enabled.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-25 02:16
Updated : 2026-08-31 20:52
NVD link : CVE-2026-76846
Mitre link : CVE-2026-76846
CVE.ORG link : CVE-2026-76846
JSON object : View
Products Affected
No product.
CWE
CWE-522
Insufficiently Protected Credentials
