Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing content editors to read sensitive configuration values. Attackers with page-content edit access can access raw configuration arrays including secrets like cache credentials by using dot notation in Twig templates, bypassing the config_denied_paths restrictions. | |
| Title | Grav CMS before 2.0.16 Information Disclosure via Twig Sandbox Bypass | |
| First Time appeared |
Getgrav
Getgrav grav |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Getgrav
Getgrav grav |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T01:30:21.127Z
Reserved: 2026-08-10T13:02:20.829Z
Link: CVE-2026-72698
No data.
Status : Received
Published: 2026-08-25T02:16:45.550
Modified: 2026-08-25T02:16:45.550
Link: CVE-2026-72698
No data.
OpenCVE Enrichment
Updated: 2026-08-25T03:30:05Z