{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/grav-cms-2.0.7---2.0.10/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-69088"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Grav CMS (2.0.7 - 2.0.10)"],"_cs_severities":["high"],"_cs_tags":["cms","rce","file-read","web-application"],"_cs_type":"advisory","_cs_vendors":["Grav"],"content_html":"\u003cp\u003eGrav CMS versions 2.0.7 through 2.0.10 are vulnerable to an arbitrary static method execution flaw (CVE-2026-69088). The vulnerability stems from insufficient input validation in the \u003ccode\u003eBlueprint::isSafeDynamicCall()\u003c/code\u003e function. While the application implements a denylist for dangerous callables, this protection is bypassed when a fully-qualified static method call (using the \u003ccode\u003eClass::method\u003c/code\u003e syntax) is utilized, as the validation check fails to evaluate strings containing the double-colon delimiter.\u003c/p\u003e\n\u003cp\u003eAn attacker with administrative page-editing access (\u003ccode\u003eadmin.pages\u003c/code\u003e) can inject a malicious directive into the form-field frontmatter of a page. When the application parses this blueprint, it executes the specified static method. By leveraging existing gadget methods within the PHP environment, an attacker can read arbitrary files accessible to the web server user or perform file/directory creation and modification. This effectively elevates privileges for a low-privileged editor to perform sensitive system operations. The issue is resolved in Grav CMS version 2.0.11.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to read any file on the server readable by the web server process and perform unauthorized file and directory operations. This can lead to the exfiltration of sensitive configuration files, source code, or internal data, as well as the modification of the web root to achieve persistent code execution. This vulnerability is particularly critical in multi-user environments where page-editing permissions are delegated to non-administrative users.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of Grav CMS to version 2.0.11 or later immediately to patch CVE-2026-69088.\u003c/li\u003e\n\u003cli\u003eReview system logs for unexpected modification of configuration files or directory structures within the web root.\u003c/li\u003e\n\u003cli\u003eAudit administrative user accounts to ensure that page-editing privileges are granted only to trusted personnel.\u003c/li\u003e\n\u003cli\u003eRestrict file system permissions for the web server user to the minimum necessary to function, specifically limiting write access to only required directories, to mitigate the impact of arbitrary file operations.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-03T16:06:15Z","date_published":"2026-08-03T16:06:15Z","id":"https://feed.craftedsignal.io/briefs/2026-08-grav-cms-rce/","summary":"Grav CMS versions 2.0.7 through 2.0.10 allow authenticated users with page-editing permissions to trigger arbitrary public static method calls via malicious blueprint directives, leading to unauthorized file read and write operations.","title":"Arbitrary Static Method Execution in Grav CMS","url":"https://feed.craftedsignal.io/briefs/2026-08-grav-cms-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Grav CMS (2.0.7 - 2.0.10)","version":"https://jsonfeed.org/version/1.1"}