HIGH 7.1 NVD
CVE-2026-72698
Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing content editors to read sensitive config
Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing content editors to read sensitive configuration values. Attackers with page-content edit access can access raw configuration arrays including secrets like cache credentials by using dot notation in Twig templates, bypassing the config_denied_paths restrictions.
References
- https://github.com/getgrav/grav/security/advisories/GHSA-p597-crqc-m349
- https://www.vulncheck.com/advisories/grav-cms-before-information-disclosure-via-twig-sandb
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-08-25 via NVD.
vulnfeed aggregates 11266 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.