Environment Variable Leak in Craft CMS by Craft
CVE-2026-72782
7.1HIGH
What is CVE-2026-72782?
Craft CMS versions from 5.0.0-RC1 to prior 5.10.6 and from 4.0.0-RC1 to prior 4.18.2 expose a vulnerability allowing authenticated attackers with control panel access to leak sensitive environment variables. By exploiting the interpolation of environment variables within Twig templates, attackers can execute a series of requests to collect critical information such as session keys and database credentials. This vulnerability poses a risk for session forgery, privilege escalation, and the unauthorized access of API, SMTP, and storage credentials.
Affected Version(s)
cms 5.0.0-RC1 < 5.10.6
cms 4.0.0-RC1 < 4.18.2
cms 5.10.6
