High severity8.4NVD Advisory· Published Aug 25, 2026· Updated Aug 31, 2026
CVE-2026-72696
CVE-2026-72696
Description
Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile() that allows local attackers to overwrite arbitrary files by pre-creating symlinks at predictable lock file paths in the world-writable temp directory. Attackers can place a symlink at the predictable lock path pointing to any file the web server process can write to, and the next scheduled job run will follow the symlink and overwrite the target file's content with the job ID string.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
2- Grav CMS: Six Vulnerabilities Disclosed, Including Twig Sandbox Escapes and Secret LeaksVypr Intelligence · Aug 25, 2026
- Grav CMS: Eight Vulnerabilities Including Path Traversal and Auth Bypass Disclosed TogetherVypr Intelligence · Aug 25, 2026