CVE-2026-65008: Grav CMS RCE via Uncontrolled Callable in Blueprint::dynamicData()
ID: fe19ded8-c80f-59a6-87d9-145783897795
STIX ID: report--fe19ded8-c80f-59a6-87d9-145783897795
Feed Name: CosmicBytez Labs
**Executive Summary:** A critical remote code execution vulnerability (CVE-2026-65008, CVSS 9.8) affects Grav CMS <= 2.0.4: Blueprint::dynamicData() passes attacker-controlled Class::method callables to call_user_func_array() without allowlist validation, allowing unauthenticated attackers (via form plugin routes) to execute arbitrary PHP functions and achieve full RCE; a patch is available in Grav 2.0.7 and the report includes mitigation steps, detection indicators, and post-remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
