PT-2026-60640 · Grav · Grav

·

CVE-2026-62230

·

Published

2026-07-17

·

Updated

2026-08-19

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grav versions prior to 2.0.4
Description An unauthenticated attacker can bypass restrictions on sensitive file types by requesting files with uppercase or mixed-case extensions (e.g., .YAML, .PHP). This occurs because the default .htaccess file and the webserver-configs/htaccess.txt reference lack the [NC] (No Case) flag, making extension matching case-sensitive. On case-insensitive filesystems, such as Windows/NTFS, macOS/HFS+, or Docker volume mounts, this allows the unauthorized reading of sensitive configuration files that may contain credentials and API keys.
Recommendations Update Grav to version 2.0.4 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62230
GHSA-VWG3-W8W3-PC79

Affected Products

Grav