CVE-2026-61454 Details
Description
The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/admin (and its subroutes). This object is returned in every unauthenticated response and discloses the server URL, API prefix, admin base path, runtime environment type, and exact Grav and Admin2 version numbers, allowing an unauthenticated attacker to fingerprint the deployment and select version-specific exploits without reconnaissance.
A vulnerability in the Grav Admin2 plugin, specifically in versions through 2.0.3, allows for unauthorized information disclosure. The plugin embeds a global JavaScript variable, window.__GRAV_CONFIG__, in the Admin2 single-page application bootstrap page at /grav/admin and its subroutes. This variable is included in every unauthenticated response and reveals sensitive deployment details such as the server URL, API prefix, admin base path, runtime environment type, and exact version numbers of Grav and Admin2. This information enables an unauthenticated attacker to fingerprint the application and target version-specific exploits without prior reconnaissance.
Users can update to Grav Admin2 plugin version 2.0.4 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 11, 2026CISA-ADP
Assessed Jul 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/getgrav/grav/security/advisories/GHSA-pfjq-chp8-3vgh | CISA-ADP | AdvisoryExploitVendor |
| https://github.com/getgrav/grav/security/advisories/GHSA-pfjq-chp8-3vgh | [email protected] | AdvisoryExploitVendor |
| https://www.vulncheck.com/advisories/grav-before-information-disclosure-via-grav-config | [email protected] | AdvisoryBroken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Grav Admin2 | <= 2.0.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 13, 2026 | CVE Modified | CISA-ADP |
| Jul 11, 2026 | New CVE Received | [email protected] |
Volerion