CVE-2026-76846: Insufficiently Protected Credentials in getgrav grav
Description
Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to system configuration secrets. Attackers with page-edit permission can use config.get() or config.toArray() in Twig templates to retrieve sensitive values like system.cache.redis.password when config_access is enabled.
CVSS v4.0
Score 8.7high
Affected software
getgrav
grav
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises from an incomplete denylist in Grav's Twig sandbox configuration (system/config/security.yaml) where the 'system' prefix is missing from the default denied paths. When operators enable the non-default 'twig_content.config_access: true' setting to expose low-sensitivity config values to editor-authored Twig content, sensitive secrets under 'system.*' such as 'system.cache.redis.password' become accessible. This exposure happens through the SandboxConfig facade's get() and toArray() methods, which are allowed inside sandboxed Twig templates. The flaw is a regression following a prior fix for secret exfiltration via config.toArray(), but the denylist shipped with Grav 2.0.15 remains incomplete. Proof-of-concept code confirms that plugin secrets are redacted but system secrets are not. The vulnerability affects Grav versions before 2.0.16.
Potential Impact
Any Grav site using Redis caching with a password and enabling the documented Twig sandbox content access settings ('twig_content.process_enabled: true' and 'twig_content.config_access: true') exposes sensitive credentials to any user with page-edit permissions. This can lead to unauthorized disclosure of secrets such as Redis passwords, potentially compromising backend services. The vulnerability requires no user privileges beyond page editing and no user interaction, making it remotely exploitable. The CVSS v4.0 score is 8.7 (high severity) reflecting network attack vector, low attack complexity, no privileges required, no user interaction, and high confidentiality impact.
Mitigation Recommendations
As of the provided information, no official patch or fix version is explicitly stated. Grav version 2.0.15 is vulnerable, and the issue is fixed in versions 2.0.16 and later. Operators should upgrade to Grav 2.0.16 or later once available to address the incomplete denylist in the Twig sandbox configuration. Until then, disabling 'twig_content.config_access' or avoiding enabling 'twig_content.process_enabled' with config access can mitigate exposure. Review and customize the 'twig_sandbox.config_denied_paths' list to include the 'system' prefix to block access to sensitive system configuration paths. Monitor the vendor advisory for official patch releases and remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-19T20:34:19.724Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8cf57bacd9273b498428b0
Added to database: 08/25/2026, 01:52:59 UTC
Last enriched: 09/18/2026, 01:27:49 UTC
Last updated: 10/08/2026, 18:48:48 UTC
Views: 92
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.