What is CVE-2026-64850?
A vulnerability in Grav's Blueprint::dynamicData() function allows arbitrary code execution by passing dangerous callback parameters to `call_user_func_array()`. This affects users with `admin.pages` or API access. Users should upgrade to Grav version 2.0.7.
Azərbaycanca: Grav platformasında Blueprint::dynamicData() funksiyası vasitəsilə `call_user_func_array()`-ə təhlükəli callback parametrləri ötürməklə ixtiyari kod icrasına yol açan boşluq aşkarlanıb. Bu zəiflik `admin.pages` və ya API girişi olan istifadəçilərə təsir edir. İstifadəçilər Grav-i 2.0.7 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: Grav
FAQ2
Which privileged users are affected by CVE-2026-64850?
This vulnerability affects users with `admin.pages` or API access.
What is the recommended solution for CVE-2026-64850?
Users should upgrade to Grav version 2.0.7.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.