Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-61454: Grav Admin2 Plugin Discloses Server Details to Unauthenticated Users
CVE-2026-61454
Summary
The Grav Admin2 plugin before version 2.0.4 reveals sensitive information about your Grav server to anyone who visits the admin page. This could help an attacker identify your server and potentially exploit known weaknesses. To fix this, update the Grav Admin2 plugin to version 2.0.4 or later.
Original title
The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/admin (and its subroutes). This...
Original description
The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/admin (and its subroutes). This object is returned in every unauthenticated response and discloses the server URL, API prefix, admin base path, runtime environment type, and exact Grav and Admin2 version numbers, allowing an unauthenticated attacker to fingerprint the deployment and select version-specific exploits without reconnaissance.
nvd CVSS3.1
5.3
nvd CVSS4.0
8.7
Vulnerability type
CWE-200
Information Exposure
Published: 11 Jul 2026 · Updated: 20 Jul 2026 · First seen: 11 Jul 2026