PT-2026-37276 · Grav · Grav

Samer666569

·

Published

2026-05-05

·

Updated

2026-05-11

·

CVE-2026-42610

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Grav versions prior to 2.0.0-beta.2
Description A low-privileged user, such as a Content Editor with pages.update permissions, can bypass Twig sandbox restrictions by utilizing the grav['accounts'] service. This allows an attacker to programmatically load administrative user objects and extract sensitive data, including Bcrypt password hashes and the security salt. This is achieved by accessing the internal service container to bypass the isDangerousFunction filter.
Recommendations Update to version 2.0.0-beta.2 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42610
GHSA-3F29-PQWF-V4J4

Affected Products

Grav