Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-76846

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published Aug 25, 2026
Vendor unknown

Description

Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to system configuration secrets. Attackers with page-edit permission can use config.get() or config.toArray() in Twig templates to retrieve sensitive values like system.cache.redis.password when config_access is enabled.

References