What is CVE-2026-69088?
Grav CMS versions 2.0.7 through 2.0.10 fail to properly validate fully-qualified static method calls in blueprint dynamic-field directives, allowing accounts with only page-editing permissions to invoke dangerous functions. Users are strongly advised to upgrade to the latest version immediately.
Azərbaycanca: Grav CMS-in 2.0.7-dən 2.0.10-a qədər versiyalarında blueprint dinamik sahə direktivlərində fully-qualified static method call-lərin (`Class::method`) düzgün yoxlanılmaması boşluğu aşkarlanıb. Bu, yalnız səhifə redaktəsi icazəsi olan hesabın təhlükəli funksiyalar çağırmasına imkan yaradır. İstifadəçilərə dərhal ən son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions of Grav CMS are affected by CVE-2026-69088?
Grav CMS versions 2.0.7 through 2.0.10 are affected by this vulnerability.
What minimum permission level does an attacker need to exploit this vulnerability?
The attacker only needs page-editing permissions to exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.