logo

Zero Installation, Total Compromise: Critical Grav CMS Exploit Chain Grants Unauthenticated RCE

ID: d6565812-fdc6-5058-9627-6c457cf6d706

STIX ID: report--d6565812-fdc6-5058-9627-6c457cf6d706

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-05-10

Date Updated: 2026-05-22

Author: Ddos

...
...

This advisory describes two critical Grav CMS vulnerabilities (CVE-2026-42613 and CVE-2026-42607) that enable an unauthenticated attacker to self-register with super-admin privileges by abusing missing server-side validation in the Login plugin, then chain that access to perform remote code execution through unsafe ZIP extraction in the Direct Install/GPM feature; administrators are urged to update to Grav 2.0.0-beta.2 or later immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.