PT-2026-76927 · Grav · Grav

·

CVE-2026-75827

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grav versions prior to 2.0.15
Description An arbitrary file write issue exists in the Blueprint dynamic-data bare-function validation due to the use of an incomplete denylist instead of a positive allowlist. Users with page-edit or blueprint-config access can trigger the error log() function via a data directive to append PHP payloads to web-accessible files, which can lead to remote code execution.
Recommendations Update Grav to version 2.0.15 or later.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75827
GHSA-F8WV-XP27-6GQ7

Affected Products

Grav