{"id":"CVE-2026-72782","title":"Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secrets (via ${ENV_VAR} strings in the elementId parameter) into Twig templates before rendering, even when the Twig sandb…","summary":"Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secrets (via ${ENV_VAR} strings in the elementId parameter) into Twig templates before rendering, even when the Twig sandb…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-668"],"vendor":"craftcms","product":"cms","affected":["cms >= 5.0.0-RC1 < 5.10.6","cms >= 4.0.0-RC1 < 4.18.2"],"published":"2026-08-11","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:17:34.943","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72782","references":[{"url":"https://github.com/craftcms/cms/security/advisories/GHSA-596p-6jv8-775v","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/craft-cms-rc1-before-environment-variable-leak","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-08-11T17:40:57.175519Z"},"epss":0.00386,"epssPercentile":0.30479,"ingestedAt":"2026-10-08T16:52:14.713Z","slug":"CVE-2026-72782","body":"## Overview\n\nCraft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secrets (via ${ENV_VAR} strings in the elementId parameter) into Twig templates before rendering, even when the Twig sandbox is enabled. An authenticated attacker with control panel access can render a malicious sandboxed Twig template and, using a blind error-based technique across many requests, incrementally leak arbitrary environment variables and secrets. These can be abused to forge sessions (via CRAFT_SECURITY_KEY), escalate privileges, and steal database, SMTP, API, or blob storage credentials. Fixed in 5.10.6 and 4.18.2.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}