What is CVE-2026-75827?
Grav CMS versions prior to 2.0.15 contain an arbitrary file write vulnerability in the Blueprint dynamic due to an incomplete denylist in bare-function validation. Attackers with page-edit or blueprint-config access can exploit this via the `error_log` function. Update to version 2.0.15 immediately.
Azərbaycanca: Grav CMS-in 2.0.15-dən əvvəlki versiyalarında Blueprint funksiyasında ixtiyari fayl yazma zəifliyi aşkarlanıb. Bu, `error_log` funksiyası vasitəsilə səhifə redaktəsi və ya blueprint konfiqurasiyası icazəsi olan hücumçulara təsir edə bilər. Dərhal 2.0.15 versiyasına yeniləmək tövsiyə olunur.
FAQ2
Which versions of Grav CMS are affected by CVE-2026-75827?
Grav CMS versions prior to 2.0.15 are affected by this arbitrary file write vulnerability.
What permissions does an attacker need to exploit CVE-2026-75827?
An attacker needs page-edit or blueprint-config access to exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.