Medium severity6.5NVD Advisory· Published Aug 25, 2026
CVE-2026-76839
CVE-2026-76839
Description
Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and offsetexists() methods that lack field filtering. Attackers with page-edit permissions can call offsetGet() on User objects to extract hashed passwords and 2FA secrets, enabling offline password cracking and authentication bypass.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.