CVE-2026-27131: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-27131 is an information disclosure vulnerability in the Sprig Plugin for Craft CMS, a reactive Twig component framework. Admin users and users with explicit permission to access the Sprig Playground could potentially expose the Craft CMS security key, credentials, and other sensitive configuration data, and could also invoke the hashData() signing function without appropriate restrictions. The vulnerability affects versions >= 2.0.0 and < 2.15.2 (v2 branch) and >= 3.0.0 and < 3.7.2 (v3 branch). It was disclosed on March 23, 2026, with patches released the same day. The CVSS v3.1 base score is 5.5 (Medium) (Github Advisory).

Technical details

The root cause is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and CWE-489 (Active Debug Code), as the Sprig Playground — a developer-oriented feature — remained accessible in production environments when devMode was enabled, without adequate access restrictions (Github Advisory). The Playground feature allows execution of arbitrary Twig expressions, which can reference Craft CMS environment variables and configuration values including the application security key and database credentials. The fix introduced a getCanAccessPlayground() method in SettingsModel.php that gates Playground access on devMode being active, and added a new enablePlaygroundWhenDevModeDisabled configuration option (defaulting to false) to explicitly control this behavior (Commit 09c9da2, Commit db18c46). Exploitation requires high privileges (admin or explicit Playground permission), limiting the attack surface to trusted but potentially malicious insiders or compromised admin accounts.

Impact

Successful exploitation allows a privileged attacker to extract highly sensitive configuration data from the Craft CMS installation, including the application security key and database credentials (Github Advisory). Exposure of the security key could enable an attacker to forge signed data via the hashData() function, potentially undermining session integrity or other cryptographic protections within the application. While availability is not impacted, the confidentiality impact is rated High, and the integrity impact is rated Low due to the ability to run the signing function. The risk is most acute in production environments where devMode was inadvertently left enabled.

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Github Advisory). The EPSS score is approximately 0.042% (13th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for high privileges (admin-level access or explicit Playground permission), significantly reducing the likelihood of opportunistic attacks.

Exploitation steps

  1. Gain privileged access: Obtain admin credentials or an account with explicit Sprig Playground access on a Craft CMS installation running a vulnerable version of the Sprig Plugin (v2.0.0–2.15.1 or v3.0.0–3.7.1) with devMode enabled.
  2. Navigate to the Sprig Playground: Access the Sprig Playground section in the Craft CMS control panel, which is available as a CP section when enablePlayground is true and devMode is active.
  3. Craft a Twig expression to extract sensitive data: Enter a Twig expression in the Playground that reads environment variables or Craft configuration values, such as {{ craft.app.config.general.securityKey }} or similar expressions referencing database credentials.
  4. Execute the expression: Submit the Playground form to evaluate the Twig expression server-side, causing the sensitive configuration data to be rendered in the Playground output.
  5. Abuse the signing function: Optionally invoke hashData() with attacker-controlled input to generate valid signed tokens, potentially enabling session forgery or other integrity attacks (Github Advisory).

Indicators of compromise

  • Logs: Craft CMS web/access logs showing authenticated requests to the Sprig Playground controller endpoint (e.g., paths containing /sprig/playground) from unexpected users or at unusual times.
  • Logs: Application logs recording Twig expression evaluations in the Playground that reference sensitive configuration variables (e.g., securityKey, database credentials).
  • Network: Outbound connections from the CMS server following Playground access, potentially indicating exfiltration of extracted credentials.
  • Application: Unexpected use of the hashData() signing function logged in Craft CMS audit logs, particularly from admin accounts not typically associated with development activity.

Mitigation and workarounds

Upgrade the Sprig Plugin to version 2.15.2 (for v2.x users) or version 3.7.2 (for v3.x users), which disable Playground access by default when devMode is not enabled (Github Advisory). As an immediate workaround for systems that cannot be patched, ensure devMode is disabled in all production Craft CMS environments, which will prevent Playground access in patched versions and reduce exposure in unpatched ones. Additionally, review and restrict Sprig Playground permissions to only essential development personnel, and set the new enablePlaygroundWhenDevModeDisabled configuration option to false (the default in patched versions) to prevent accidental re-enablement (Commit 09c9da2).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management