{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3agravcms_comments_plugin/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:grav:cms_comments_plugin:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-100672"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Grav CMS Comments plugin (\u003c= 1.2.10)"],"_cs_severities":["high"],"_cs_tags":["cms","authentication-bypass","webserver","information-disclosure"],"_cs_type":"threat","_cs_vendors":["Grav"],"content_html":"\u003cp\u003eThe Comments plugin for Grav CMS (getgrav/grav-plugin-comments) through version 1.2.10 contains a critical authentication bypass vulnerability (CVE-2026-100672). The plugin registers an admin handler that fails to verify the authentication state of the requester, relying instead on an incorrect check (isAdmin()) that only validates the presence of the admin service on the requested route. This flaw allows an unauthenticated remote attacker to query the /admin/comments/page: endpoints. Because this handler executes during the plugin stage before the Admin plugin initiates its standard login procedures, attackers can bypass authentication entirely. Successful exploitation results in the unauthorized disclosure of sensitive comment metadata, including commenter email addresses and absolute server filesystem paths, which can facilitate further reconnaissance against the hosting environment. This issue does not affect the Grav 2.0 Admin Next stack.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability leads to the unauthorized exfiltration of site comment data, exposing PII such as email addresses and revealing internal server directory structures. This information leak aids attackers in conducting targeted phishing or mapping the backend filesystem to identify further attack surfaces.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Grav CMS Comments plugin to version 1.2.11 or later to remediate CVE-2026-100672.\u003c/li\u003e\n\u003cli\u003eAudit logs for suspicious GET requests to the /admin/comments/ path from unauthenticated sources or anomalous IPs.\u003c/li\u003e\n\u003cli\u003eRestrict access to the /admin/ directory at the web server level (e.g., using Nginx or Apache allowlisting) if the update cannot be applied immediately.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-26T15:10:05Z","date_published":"2026-09-26T15:10:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-grav-comments-vuln/","summary":"An authentication bypass vulnerability in the Grav CMS Comments plugin through version 1.2.10 allows unauthenticated attackers to exfiltrate comment data, including emails and server paths, via an improperly secured admin handler.","title":"Authentication Bypass in Grav CMS Comments Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-grav-comments-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:grav:cms_comments_plugin:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}