Zero Installation, Total Compromise: Critical Grav CMS Exploit Chain Grants Unauthenticated RCE
ID: d6565812-fdc6-5058-9627-6c457cf6d706
STIX ID: report--d6565812-fdc6-5058-9627-6c457cf6d706
Feed Name: securityonline.info
Threat Score
This advisory describes two critical Grav CMS vulnerabilities (CVE-2026-42613 and CVE-2026-42607) that enable an unauthenticated attacker to self-register with super-admin privileges by abusing missing server-side validation in the Login plugin, then chain that access to perform remote code execution through unsafe ZIP extraction in the Direct Install/GPM feature; administrators are urged to update to Grav 2.0.0-beta.2 or later immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
