logo

CVE-2026-65008: Grav CMS RCE via Uncontrolled Callable in Blueprint::dynamicData()

ID: fe19ded8-c80f-59a6-87d9-145783897795

STIX ID: report--fe19ded8-c80f-59a6-87d9-145783897795

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

...
...

**Executive Summary:** A critical remote code execution vulnerability (CVE-2026-65008, CVSS 9.8) affects Grav CMS <= 2.0.4: Blueprint::dynamicData() passes attacker-controlled Class::method callables to call_user_func_array() without allowlist validation, allowing unauthenticated attackers (via form plugin routes) to execute arbitrary PHP functions and achieve full RCE; a patch is available in Grav 2.0.7 and the report includes mitigation steps, detection indicators, and post-remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.