Exposure of Resource to Wrong Sphere in Craft CMS - #VU139967

 

Exposure of Resource to Wrong Sphere in Craft CMS - #VU139967

Published: July 29, 2026


Vulnerability identifier: #VU139967
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-668
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to exposure of sensitive resources in the Twig template rendering functionality when processing a crafted `elementId` parameter that interpolates environment variable references. A remote user can render a malicious sandboxed Twig template and use repeated error-based requests to disclose sensitive information.

Exploitation requires permission to access the control panel and can occur even when the Twig sandbox is enabled through `enableTwigSandbox()`.


Affected software

Craft CMS

Remediation

Install security update from vendor's website.

Craft CMS - addressed in versions 4.18.2, 5.10.6

External References

Related Security Bulletins