CVE-2026-76839: Getgrav Grav

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and offsetexists() methods that lack field filtering. Attackers with page-edit permissions can call offsetGet() on User objects to extract hashed passwords and 2FA secrets, enabling offline password cracking and authentication bypass.

Affected products

  • Getgrav Grav: before 2.0.16 (fixed in 2.0.16)

Published 2026-08-25. Last modified 2026-10-08.