CVE-2026-76846

Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to system configuration secrets. Attackers with page-edit permission can use config.get() or config.toArray() in Twig templates to retrieve sensitive values like system.cache.redis.password when config_access is enabled.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-25 02:16

Updated : 2026-08-31 20:52


NVD link : CVE-2026-76846

Mitre link : CVE-2026-76846

CVE.ORG link : CVE-2026-76846


JSON object : View

Products Affected

No product.

CWE
CWE-522

Insufficiently Protected Credentials