{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/grav-cms--2.0.13/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-72819"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Grav CMS (\u003c 2.0.13)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","rce","ssti","cms"],"_cs_type":"advisory","_cs_vendors":["getgrav"],"content_html":"\u003cp\u003eGrav CMS versions prior to 2.0.13 contain a critical vulnerability in the Flex Objects plugin (CVE-2026-72819) that facilitates remote code execution. The vulnerability stems from insufficient validation of plugin settings during the handling of ZIP archive uploads. Authenticated attackers can bypass security checks by manipulating input parameters, specifically by utilizing array notation instead of the expected string notation. This technique allows an attacker to manipulate the underlying routine name validation, successfully invoking the unZip routine with a crafted, malicious archive. By doing so, the attacker can extract arbitrary PHP files directly into the web root, which can subsequently be executed by the web server. This vulnerability allows for full code execution in the context of the web application user, posing a significant risk to the integrity and confidentiality of the host environment. Defenders should prioritize patching to version 2.0.13 or later.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains authenticated access to the Grav CMS administrative interface or another area allowing interaction with the Flex Objects plugin.\u003c/li\u003e\n\u003cli\u003eAttacker prepares a ZIP archive containing a web shell or malicious PHP script intended for execution on the server.\u003c/li\u003e\n\u003cli\u003eAttacker initiates an upload process via the Flex Objects plugin, intercepting the request to modify input parameters.\u003c/li\u003e\n\u003cli\u003eAttacker replaces standard string-based input with array notation in the request to bypass the plugin's routine name validation filters.\u003c/li\u003e\n\u003cli\u003eThe server-side validation logic fails to correctly parse the array notation, incorrectly validating the input and proceeding to the internal unZip routine.\u003c/li\u003e\n\u003cli\u003eThe unZip routine processes the attacker-supplied malicious archive and extracts the contained PHP files into a directory accessible within the web root.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the location of the newly extracted PHP file in the web browser to trigger server-side execution.\u003c/li\u003e\n\u003cli\u003eSuccessful execution of the payload grants the attacker code execution, potentially leading to full system compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-72819 results in complete remote code execution on the server hosting the Grav CMS installation. This level of access typically leads to total compromise of the application, including the ability to read or modify sensitive data, install further persistent backdoors, and move laterally within the network. The scope of impact is confined to organizations utilizing vulnerable versions of Grav CMS prior to 2.0.13.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update all instances of Grav CMS to version 2.0.13 or later to remediate CVE-2026-72819.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for suspicious POST requests targeting Flex Objects plugin endpoints that contain array notation (e.g., brackets like \u003ccode\u003e[]\u003c/code\u003e or nested array structures) in the request parameters.\u003c/li\u003e\n\u003cli\u003eRestrict access to administrative and plugin-upload functionality to trusted internal IP ranges or VPN-only access to prevent exploitation by external, authenticated attackers.\u003c/li\u003e\n\u003cli\u003eMonitor the web directory for the creation of unexpected \u003ccode\u003e.php\u003c/code\u003e files, particularly those uploaded through the web interface, as indicated by file access or modification logs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T14:12:24Z","date_published":"2026-08-14T14:12:10Z","id":"https://feed.craftedsignal.io/briefs/2026-08-grav-cms-rce/","summary":"Authenticated users can achieve remote code execution in Grav CMS versions prior to 2.0.13 by exploiting improper input validation in the Flex Objects plugin to upload and execute arbitrary PHP files.","title":"Remote Code Execution in Grav CMS Flex Objects Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-grav-cms-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Grav CMS (\u003c 2.0.13)","version":"https://jsonfeed.org/version/1.1"}