CVE-2026-76846: Getgrav Grav

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to system configuration secrets. Attackers with page-edit permission can use config.get() or config.toArray() in Twig templates to retrieve sensitive values like system.cache.redis.password when config_access is enabled.

Affected products

  • Getgrav Grav: before 2.0.16 (fixed in 2.0.16)

Published 2026-08-25. Last modified 2026-10-08.