PT-2026-71988 · Grav Cms · Grav Cms+1

·

CVE-2026-72819

·

Published

2026-08-14

·

Updated

2026-08-14

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grav CMS versions prior to 2.0.13
Description Authenticated users can achieve remote code execution through a flaw in the Flex Objects plugin settings validation. By utilizing array notation instead of string notation, an attacker can bypass routine name validation to call the unZip() routine with a malicious ZIP archive. This process allows the upload and writing of PHP files directly to the web root for subsequent execution.
Recommendations Update Grav CMS to version 2.0.13 or later.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72819
GHSA-R94F-HX44-8JQF

Affected Products

Flex Objects
Grav Cms