Medium severity6.5NVD Advisory· Published Aug 25, 2026· Updated Aug 31, 2026
CVE-2026-76839
CVE-2026-76839
Description
Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and offsetexists() methods that lack field filtering. Attackers with page-edit permissions can call offsetGet() on User objects to extract hashed passwords and 2FA secrets, enabling offline password cracking and authentication bypass.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
getgrav/gravPackagist | < 2.0.16 | 2.0.16 |
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
1- Grav CMS: Six Vulnerabilities Disclosed, Including Twig Sandbox Escapes and Secret LeaksVypr Intelligence · Aug 25, 2026