---
id: CVE-2026-72782
title: >-
  Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2
  interpolate environment variables and secrets (via ${ENV_VAR} strings in the
  elementId parameter) into Twig templates before rendering, even when the Twig
  sandb…
summary: >-
  Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2
  interpolate environment variables and secrets (via ${ENV_VAR} strings in the
  elementId parameter) into Twig templates before rendering, even when the Twig
  sandb…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-668
vendor: craftcms
product: cms
affected:
  - cms >= 5.0.0-RC1 < 5.10.6
  - cms >= 4.0.0-RC1 < 4.18.2
published: '2026-08-11'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:34.943'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-72782'
references:
  - url: 'https://github.com/craftcms/cms/security/advisories/GHSA-596p-6jv8-775v'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/craft-cms-rc1-before-environment-variable-leak
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-11T17:40:57.175519Z'
epss: 0.00386
epssPercentile: 0.30479
ingestedAt: '2026-10-08T16:52:14.713Z'
---

## Overview

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secrets (via ${ENV_VAR} strings in the elementId parameter) into Twig templates before rendering, even when the Twig sandbox is enabled. An authenticated attacker with control panel access can render a malicious sandboxed Twig template and, using a blind error-based technique across many requests, incrementally leak arbitrary environment variables and secrets. These can be abused to forge sessions (via CRAFT_SECURITY_KEY), escalate privileges, and steal database, SMTP, API, or blob storage credentials. Fixed in 5.10.6 and 4.18.2.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
