High severity7.5NVD Advisory· Published Aug 25, 2026· Updated Aug 31, 2026
CVE-2026-76846
CVE-2026-76846
Description
Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to system configuration secrets. Attackers with page-edit permission can use config.get() or config.toArray() in Twig templates to retrieve sensitive values like system.cache.redis.password when config_access is enabled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
getgrav/gravPackagist | < 2.0.16 | 2.0.16 |
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
1- Grav CMS: Six Vulnerabilities Disclosed, Including Twig Sandbox Escapes and Secret LeaksVypr Intelligence · Aug 25, 2026