PT-2026-81145 · Grav Cms · Grav Cms

·

CVE-2026-72702

·

Published

2026-08-25

·

Updated

2026-08-28

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grav CMS versions prior to 2.0.16
Description An origin validation bypass exists in the Uri::referrer() and Pages::referrerRoute() methods. The issue occurs because the Referer header is validated using an unanchored string prefix match via str starts with($referrer, $base) without a trailing delimiter. This allows an attacker controlling a domain that starts with the victim site's origin to send a request that is incorrectly treated as same-origin, bypassing the origin check.
Recommendations Update Grav CMS to version 2.0.16 or later.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72702
GHSA-9CCQ-2JFG-QW33

Affected Products

Grav Cms