HIGH 8.7 NVD
CVE-2026-76846
Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to system configuration secrets. Attacke
Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to system configuration secrets. Attackers with page-edit permission can use config.get() or config.toArray() in Twig templates to retrieve sensitive values like system.cache.redis.password when config_access is enabled.
References
- https://github.com/getgrav/grav/security/advisories/GHSA-xjw5-q542-3vmr
- https://www.vulncheck.com/advisories/grav-before-information-disclosure-via-twig-sandbox
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-08-25 via NVD.
vulnfeed aggregates 11266 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.