Description
Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled (system.debugger.enabled: true, which is not the default), the Clockwork profiler endpoint is exposed without authentication: InitializeProcessor::handleDebuggerRequest() intercepts any path containing /__clockwork/ during bootstrap and passes it to Debugger::debuggerRequest(), which performs no user lookup, IP restriction, or Clockwork authenticator check, and also supports anonymous pagination over the entire stored history. With the shipped censored: false default, each stored record contains raw request cookies (including Grav's session cookie, whose value is the PHP session id, allowing an attacker to resume another user's session, including an authenticated admin's), the full parsed request body (Grav's login form posts data[username]/data[password], so passwords are stored in plaintext because Clockwork's password filter only inspects top-level keys), and the site's entire system and plugin configuration, including operator-saved secrets such as SMTP credentials, third-party API keys, and licence keys. Authorization and X-API-Token headers are stored even when censored: true. On Grav 2.0, setting provider: debugbar does not avoid the issue because Grav forces the Clockwork provider for requests preferring a JSON response. The issue is fixed in 1.7.53.4 and 2.0.22, which restrict /__clockwork/ to server-local requests or requests presenting the new system.debugger.token secret and strip cookies and credential headers from stored records. Workarounds include setting debugger.enabled: false or blocking /__clockwork/ at the web server or CDN.
Published: 2026-09-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via unfiltered debugger endpoint
Action: Apply Patch
AI Analysis

Impact

A flaw in the Grav CMS allows attackers to access the Clockwork profiler endpoint without authentication when the system debugger is enabled. The endpoint returns all stored debugging data, including raw request cookies that contain the PHP session ID, the full request body with unfiltered credentials, and the site configuration with secrets such as SMTP and API keys. Because the profiler does not enforce any user lookup, IP restriction, or authenticator check, any web client can query the data and obtain sensitive information that could be reused to impersonate another user or compromise the site.

Affected Systems

The issue affects Grav CMS versions from 1.7.0 through 1.7.53.2 and from 2.0.0 through 2.0.21. This includes all installations of the Grav flat-file CMS where the debugger feature is enabled in the configuration. The vulnerability is identified by the vendor getgrav for the product Grav.

Risk and Exploitability

The flaw carries a CVSS score of 8.7, indicating high severity, and its EPSS score is currently unavailable but the lack of authentication makes exploitation straightforward. The vulnerability is not yet listed in CISA’s KEV catalog. An attacker can exploit it by sending a request to /__clockwork/ while the debugger is enabled, retrieving the entire debugging history, and using the captured session id to hijack an admin session or expose plaintext passwords and configuration secrets.

Generated by OpenCVE AI on September 18, 2026 at 06:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Grav to version 1.7.53.4 or 2.0.22 or later, where the /__clockwork/ endpoint is restricted and sensitive data is removed from stored records.
  • Set system.debugger.enabled to false in the Grav configuration to disable the debugger entirely.
  • Configure the web server or CDN to block access to the /__clockwork/ URI.

Generated by OpenCVE AI on September 18, 2026 at 06:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled (system.debugger.enabled: true, which is not the default), the Clockwork profiler endpoint is exposed without authentication: InitializeProcessor::handleDebuggerRequest() intercepts any path containing /__clockwork/ during bootstrap and passes it to Debugger::debuggerRequest(), which performs no user lookup, IP restriction, or Clockwork authenticator check, and also supports anonymous pagination over the entire stored history. With the shipped censored: false default, each stored record contains raw request cookies (including Grav's session cookie, whose value is the PHP session id, allowing an attacker to resume another user's session, including an authenticated admin's), the full parsed request body (Grav's login form posts data[username]/data[password], so passwords are stored in plaintext because Clockwork's password filter only inspects top-level keys), and the site's entire system and plugin configuration, including operator-saved secrets such as SMTP credentials, third-party API keys, and licence keys. Authorization and X-API-Token headers are stored even when censored: true. On Grav 2.0, setting provider: debugbar does not avoid the issue because Grav forces the Clockwork provider for requests preferring a JSON response. The issue is fixed in 1.7.53.4 and 2.0.22, which restrict /__clockwork/ to server-local requests or requests presenting the new system.debugger.token secret and strip cookies and credential headers from stored records. Workarounds include setting debugger.enabled: false or blocking /__clockwork/ at the web server or CDN.
Title Grav through 2.0.21 Unauthenticated Information Disclosure via Clockwork
First Time appeared Getgrav
Getgrav grav
Weaknesses CWE-200
CPEs cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*
cpe:2.3:a:getgrav:grav:-:*:*:*:*:*:*:*
Vendors & Products Getgrav
Getgrav grav
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-30T17:20:34.882Z

Reserved: 2026-09-17T11:07:29.772Z

Link: CVE-2026-92916

cve-icon Vulnrichment

Updated: 2026-09-18T20:03:43.160Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T12:18:30.710

Modified: 2026-09-30T18:18:42.657

Link: CVE-2026-92916

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:00:08Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor