What is CVE-2026-72820?
The vulnerability in Grav versions prior to 2.0.13 arises from improper validation of backup profile root paths, allowing attackers with profile editor access to archive directories outside GRAV_ROOT and expose sensitive files. Users should immediately upgrade to the latest Grav version to mitigate this directory traversal risk.
Azərbaycanca: Zəiflik Grav CMS-in 2.0.13-dən əvvəlki versiyalarında ehtiyat profilinin kök yolunun düzgün yoxlanılmaması səbəbindən yaranır. Bu, profil redaktə icazəsi olan hücumçulara GRAV_ROOT-dən kənar qovluqları arxivləşdirməyə imkan verir, nəticədə həssas fayllar ifşa oluna bilər. İstifadəçilərə dərhal Grav-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: Grav
FAQ2
Which versions of Grav CMS are affected by CVE-2026-72820?
This vulnerability affects Grav CMS versions prior to 2.0.13.
What permission does an attacker need to exploit CVE-2026-72820?
The attacker needs to have profile editor access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.