What is CVE-2026-72819?
A remote code execution vulnerability exists in Grav CMS before version 2.0.13 within the Flex Objects plugin, allowing authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code. Attackers can bypass file name validation using array notation. Upgrading to Grav CMS 2.0.13 or later is strongly recommended.
Azərbaycanca: Grav CMS-in 2.0.13-dən əvvəlki versiyaları Flex Objects plaginində autentifikasiya olunmuş istifadəçilərə PHP kodu olan ZIP faylı yükləməklə ixtiyari kod icrasına imkan verən boşluq aşkarlanıb. Bu zəiflik ad yoxlamasından yan keçməyə şərait yaradır. Təhlükəsizlik üçün Grav CMS-i dərhal 2.0.13 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
Does exploiting CVE-2026-72819 require authentication?
Yes, this vulnerability can only be exploited by authenticated users. An attacker can achieve arbitrary code execution by uploading a ZIP file containing PHP code to the Flex Objects plugin.
Which version should be upgraded to in order to mitigate CVE-2026-72819?
It is strongly recommended to upgrade to Grav CMS version 2.0.13 or later. Versions prior to 2.0.13 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.