{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/grav-cms-2.0.15/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.4,"id":"CVE-2026-72696"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Grav CMS (2.0.15)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","cms","file-write"],"_cs_type":"advisory","_cs_vendors":["Grav CMS"],"content_html":"\u003cp\u003eGrav CMS versions prior to 2.0.16 contain a security flaw in the Scheduler Job::createLockFile() method, which fails to securely handle the creation of lock files in temporary directories. Because the application utilizes predictable file paths within world-writable directories for its locking mechanism, a local attacker can create a symbolic link at the expected lock file location. When the Grav CMS scheduler executes, it follows this symbolic link to the attacker-specified target and overwrites the target file with a job ID string. This vulnerability effectively allows an attacker with local user access to corrupt or overwrite any file accessible to the web server process, potentially leading to privilege escalation or service disruption depending on the targeted files.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows local attackers to overwrite arbitrary files with the privileges of the web server user. This can be used to disable security controls, corrupt configuration files, or facilitate further system-level compromise. The vulnerability affects all Grav CMS installations prior to version 2.0.16.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Grav CMS to version 2.0.16 or later immediately to address the insecure lock file handling in the Scheduler component.\u003c/li\u003e\n\u003cli\u003eReview directory permissions on the host system to ensure that web-writable temporary directories are not world-writable, limiting the ability of local users to place arbitrary symlinks.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual file write activity originating from the web server user process, particularly within critical system directories.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T04:06:26Z","date_published":"2026-08-25T04:06:26Z","id":"https://feed.craftedsignal.io/briefs/2026-08-grav-cms-symlink/","summary":"Grav CMS versions before 2.0.16 are vulnerable to arbitrary file overwrites via a symlink following flaw in the Scheduler component's lock file creation process.","title":"Arbitrary File Overwrite in Grav CMS via Symlink Following","url":"https://feed.craftedsignal.io/briefs/2026-08-grav-cms-symlink/"}],"language":"en","title":"CraftedSignal Threat Feed - Grav CMS (2.0.15)","version":"https://jsonfeed.org/version/1.1"}