Environment Variable Leak in Craft CMS by Craft
CVE-2026-72782

7.1HIGH

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72782?

Craft CMS versions from 5.0.0-RC1 to prior 5.10.6 and from 4.0.0-RC1 to prior 4.18.2 expose a vulnerability allowing authenticated attackers with control panel access to leak sensitive environment variables. By exploiting the interpolation of environment variables within Twig templates, attackers can execute a series of requests to collect critical information such as session keys and database credentials. This vulnerability poses a risk for session forgery, privilege escalation, and the unauthorized access of API, SMTP, and storage credentials.

Affected Version(s)

cms 5.0.0-RC1 < 5.10.6

cms 4.0.0-RC1 < 4.18.2

cms 5.10.6

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.