
CVE-2026-44738 Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.pages role to call config.toArray() from within a … https://www.cve.org/CVERecord?id=CVE-2026-44738
Post summary
The text announces a new vulnerability in Grav (CVE-2026-44738) where prior to 2.0.0-rc.2, the Twig sandbox allow‑list permits admin.pages users to invoke config.toArray(), providing initial technical details of the flaw.
