CVE-2026-76839 HIGH

CVE-2026-76839: Grav before 2.0.16 Information Disclosure via offsetGet

Vendor Getgrav
Product grav
Weakness CWE-522 · Insufficiently protected credentials
Published August 25, 2026
Last update August 25, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and offsetexists() methods that lack field filtering. Attackers with page-edit permissions can call offsetGet() on User objects to extract hashed passwords and 2FA secrets, enabling offline password cracking and authentication bypass.

Key dates

02Disclosure timeline

August 25, 2026 CVE published
August 25, 2026 Record updated