Ciberseguridadlatam
Critical Vulnerabilities in Grav Plugin Allow Privilege Escalation and RCE
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Two critical vulnerabilities (CVE-2026-72829 and CVE-2026-72824) were discovered in the Grav plugin API, published on 2026-08-14. CVE-2026-72829 allows privilege escalation using restricted API keys, enabling the creation of super-admin accounts. CVE-2026-72824 permits remote code execution (RCE) due to a flawed permission check, exposing servers with specific Twig configurations. Organizations using the Grav CMS are at risk, particularly those relying on limited API key permissions. The vulnerabilities have been classified as critical by the National Vulnerability Database. Immediate action is recommended to mitigate potential exploitation. No patches have been reported yet, increasing the urgency for system administrators to secure their installations.
Key Points: • CVE-2026-72829 allows privilege escalation via restricted API keys in Grav plugin. • CVE-2026-72824 enables remote code execution due to improper permission checks. • Both vulnerabilities are classified as critical, affecting Grav CMS installations.