What is CVE-2026-72827?
A server-side template injection vulnerability exists in Grav CMS versions before 2.0.13 within email-action parameters. This allows low-privileged page editors to execute arbitrary OS commands by injecting Twig payloads using the unsandboxed 'find' filter. Affected systems should be immediately upgraded to version 2.0.13 or later.
Azərbaycanca: Grav CMS-in 2.0.13-dən əvvəlki versiyalarında email-action parametrlərində server-side template injection zəifliyi aşkarlanıb. Bu, aşağı səlahiyyətli səhifə redaktorlarına Twig 'find' filteri vasitəsilə əməliyyat sistemi əmrlərini icra etməyə imkan verir. Təsirə məruz qalan sistemlərdə dərhal 2.0.13 və ya daha yeni versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which versions of Grav CMS are affected by CVE-2026-72827?
Versions before 2.0.13 are affected. It is recommended to upgrade to version 2.0.13 or later to remediate the vulnerability.
What can an attacker achieve by exploiting CVE-2026-72827?
A low-privileged page editor can execute arbitrary OS commands via server-side template injection (SSTI) using the unsandboxed Twig 'find' filter within email-action parameters.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.