CVE-2026-100671 | Getgrav Grav up to 2.0.24 Twig Sandbox process.twig applyTwigContentDefault authentication replay
A vulnerability described as critical has been identified in Getgrav Grav up to 2.0.24. Affected by this issue is the function Security::applyTwigContentDefault of the file process.twig of the component Twig Sandbox. The manipulation results in authentication bypass by capture-replay.
This vulnerability is known as CVE-2026-100671. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More