A vulnerability identified as problematic has been detected in Craft CMS up to 4.18.1/5.10.5. The impacted element is an unknown function of the component Twig Sandbox. Performing a manipulation of the argument elementId results in information disclosure.

This vulnerability is identified as CVE-2026-72782. The attack can be initiated remotely. There is not any exploit available.

You should upgrade the affected component.