VYPR
Medium severity6.5NVD Advisory· Published Aug 25, 2026· Updated Aug 31, 2026

CVE-2026-72698

CVE-2026-72698

Description

Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing content editors to read sensitive configuration values. Attackers with page-content edit access can access raw configuration arrays including secrets like cache credentials by using dot notation in Twig templates, bypassing the config_denied_paths restrictions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
getgrav/gravPackagist
< 2.0.162.0.16

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

1