Information Disclosure in Grav CMS by Getgrav
CVE-2026-72698
7.1HIGH
What is CVE-2026-72698?
Grav CMS versions prior to 2.0.16 contain a vulnerability that disrupts the sandboxing of Twig renders. This flaw allows content editors to exploit the system, allowing access to sensitive configuration values stored within system, site, and theme configuration arrays. By leveraging dot notation in Twig templates, attackers possessing page-content edit access can circumvent config_denied_paths restrictions, leading to potential exposure of sensitive data such as cache credentials.
Affected Version(s)
grav 0 < 2.0.16
grav 2.0.16
