Information Disclosure in Grav CMS by Getgrav
CVE-2026-72698

7.1HIGH

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-72698?

Grav CMS versions prior to 2.0.16 contain a vulnerability that disrupts the sandboxing of Twig renders. This flaw allows content editors to exploit the system, allowing access to sensitive configuration values stored within system, site, and theme configuration arrays. By leveraging dot notation in Twig templates, attackers possessing page-content edit access can circumvent config_denied_paths restrictions, leading to potential exposure of sensitive data such as cache credentials.

Affected Version(s)

grav 0 < 2.0.16

grav 2.0.16

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

alham-rizvi
.