CVE-2026-64850

8.7

getgrav · grav

Grav versions prior to 2.0.7 are susceptible to a code injection vulnerability that allows authenticated users to execute arbitrary code.

Executive summary

A critical code injection vulnerability in Grav versions before 2.0.7 enables authenticated attackers to execute arbitrary code on the underlying server.

Vulnerability

The platform is susceptible to improper control of code generation (CWE-94), which, when triggered by an authenticated user, allows for the injection and execution of arbitrary code.

Business impact

An attacker capable of executing arbitrary code can gain full control over the web server, leading to total compromise of the application and its data. With a CVSS score of 8.7, this represents a critical risk to the business, including the potential for data exfiltration and complete system takeover.

Remediation

Immediate Action: Update Grav to version 2.0.7 or later immediately to patch the code injection vulnerability.

Proactive Monitoring: Monitor server logs for suspicious system-level commands or file modifications that deviate from standard Grav operations.

Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to detect and block common code injection patterns and malicious payloads targeting the Grav environment.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for complete system compromise via code injection, it is imperative to apply the 2.0.7 update without delay. Users should also audit their current configurations to ensure no malicious persistence mechanisms were established prior to the update.

More getgrav CVEs