File-Based Web Platform Vulnerability in Grav by GetGrav
CVE-2026-61842

6.5MEDIUM

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-61842?

The file-based web platform Grav has a vulnerability where the Twig content sandbox allows users with page-author permissions to improperly access and display raw configuration objects. This can lead to leaks of sensitive information such as SMTP credentials, API keys, and database credentials, potentially compromising the security of the entire application. The issue has been addressed in version 2.0.2 to prevent unauthorized access to this critical data.

Affected Version(s)

grav < 2.0.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.