PT-2026-99340 · Grav+2 · Grav+2

·

CVE-2026-100669

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grav versions prior to 2.0.25
Description Web server configuration samples contain access-control deny rules that are matched case-sensitively. In the web.config file for IIS, several deny rules (including user sensitive folders, user accounts, user data, user error redirect, user pages, system, vendor, and ignore folders) set ignoreCase="false" on the URL Rewrite <match> element. This overrides the IIS default and prevents case-insensitive fallback. On IIS running over case-insensitive NTFS, an unauthenticated remote attacker can bypass these rules by varying the case of a folder name or file extension, potentially disclosing sensitive data such as configuration secrets or account password hashes. The ability to retrieve files depends on MIME registration; for example, .json files are served by default, while .yaml or .yml files may return an HTTP 404.3 error unless a YAML MIME mapping is configured. A similar issue exists in lighttpd.conf where rules for user/(config|env), directory, script-extension, root-file, and dotfile lack the (?i) modifier, which enables case-insensitive matching.
Recommendations Update to version 2.0.25 and manually re-copy the corrected sample files for web.config and lighttpd.conf after upgrading.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100669
GHSA-PG8V-XW58-FRQ8

Affected Products

Grav
Iis
Lighttpd