Grav · Grav · CVE-2026-100669
**Name of the Vulnerable Software and Affected Versions**
Grav versions prior to 2.0.25
**Description**
Web server configuration samples contain access-control deny rules that are matched case-sensitively. In the `web.config` file for IIS, several deny rules (including `user sensitive folders`, `user accounts`, `user data`, `user error redirect`, `user pages`, `system`, `vendor`, and `ignore folders`) set `ignoreCase="false"` on the URL Rewrite `<match>` element. This overrides the IIS default and prevents case-insensitive fallback. On IIS running over case-insensitive NTFS, an unauthenticated remote attacker can bypass these rules by varying the case of a folder name or file extension, potentially disclosing sensitive data such as configuration secrets or account password hashes. The ability to retrieve files depends on MIME registration; for example, `.json` files are served by default, while `.yaml` or `.yml` files may return an HTTP 404.3 error unless a YAML MIME mapping is configured. A similar issue exists in `lighttpd.conf` where rules for `user/(config|env)`, `directory`, `script-extension`, `root-file`, and `dotfile` lack the `(?i)` modifier, which enables case-insensitive matching.
**Recommendations**
Update to version 2.0.25 and manually re-copy the corrected sample files for `web.config` and `lighttpd.conf` after upgrading.