What is CVE-2026-62673?
CVE-2026-62673 affects the Grav web platform. In versions prior to 2.0.4, the .htaccess security rules miss the [NC] flag, causing case-sensitive comparison of sensitive directory and file-extension patterns. On case-insensitive filesystems, this allows unauthenticated requesters to potentially access restricted resources.
Azərbaycanca: CVE-2026-62673 Grav veb platformunda aşkarlanıb. 2.0.4 versiyasından əvvəlki versiyalarda .htaccess faylındakı təhlükəsizlik qaydaları [NC] bayrağını buraxdığı üçün həssas qovluq və fayl genişləndirmələri böyük/kiçik hərf həssaslığı ilə müqayisə edilir. Bu, hərf həssaslığı olmayan fayl sistemlərində autentifikasiya olunmamış şəxslərin məhdud mənbələrə giriş əldə etməsinə səbəb ola bilər.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What impact does CVE-2026-62673 have on the Grav platform?
Due to the missing [NC] flag in the .htaccess rules, this vulnerability can allow unauthenticated requesters to access restricted resources on case-insensitive filesystems.
Which versions of Grav are affected by CVE-2026-62673?
This vulnerability is identified in all versions of the Grav web platform prior to 2.0.4.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.