Executive brief
Craft CMS, a popular web content management system, interpolates sensitive environment variables and secrets into Twig templates before rendering, even when sandbox protections are enabled. An authenticated user with control panel access can exploit this to leak secrets like database credentials, API keys, and session signing keys through blind error-based attacks, potentially leading to privilege escalation, session forgery, or credential theft.
Technical details
The vulnerability exists in Craft CMS's elementId parameter processing, which interpolates environment variable references (${ENV_VAR} syntax) into Twig templates before rendering, even when the Twig sandbox is enabled. The sandboxed template cannot access network functions to directly exfiltrate values, but an attacker can use blind error-based injection techniques—similar to blind SQL injection—across many requests to incrementally leak arbitrary environment variables and secrets. Attack preconditions include authentication and control panel access. The vulnerability was patched in versions 5.10.6 and 4.18.2 by disabling environment variable interpolation in sandboxed contexts.
Affected products
- Craft CMS >=5.0.0-RC1, <5.10.6; >=4.0.0-RC1, <4.18.2
Timeline
- 2026-07-25: disclosed
- 2026-08-11: advisory: CVE-2026-72782 published
- 2026-07-25: patched: Patches released in versions 5.10.6 and 4.18.2