CVE-2026-76839: Getgrav Grav
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and offsetexists() methods that lack field filtering. Attackers with page-edit permissions can call offsetGet() on User objects to extract hashed passwords and 2FA secrets, enabling offline password cracking and authentication bypass.
Affected products
- Getgrav Grav: before 2.0.16 (fixed in 2.0.16)
Published 2026-08-25. Last modified 2026-10-08.