VYPR
advisoryPublished Sep 26, 2026· Updated Sep 28, 2026· 1 source

Grav CMS: Seven Vulnerabilities Disclosed Together, Including Privilege Escalation and XSS

Key findings • Seven vulnerabilities in Grav CMS and its plugins were disclosed on September 26, 2026. • High severity flaws include privilege escalation (CVE-2026-100670) and stored XSS (CVE…

Key findings

  • Seven vulnerabilities in Grav CMS and its plugins were disclosed on September 26, 2026.
  • High severity flaws include privilege escalation (CVE-2026-100670) and stored XSS (CVE-2026-100673).
  • Issues affect core CMS features, plugins like Data Manager and Comments, and authentication mechanisms.
  • Vulnerabilities range from Twig sandbox escapes to insecure JSON handlers and configuration weaknesses.
  • Affected versions span multiple Grav CMS releases and specific plugin versions.

On September 26, 2026, a batch of seven vulnerabilities was disclosed for the Grav CMS, with several impacting core functionality and plugins. The vulnerabilities, ranging in severity from Medium to High, were all published on the same day, indicating a coordinated disclosure event. These findings highlight potential security weaknesses in how Grav CMS handles user-generated content, authentication, and configuration.

One significant vulnerability, CVE-2026-100670 (High, CVSSv3 8.8), resides in Grav CMS versions 2.0.14 through 2.0.24. It involves a privilege escalation flaw within group and account blueprints. The vulnerability arises from an access map that is guarded by security@: admin.super but can be bypassed by submitting a flat dot-notation key, such as access.admin.super, instead of the correctly nested access[admin][super]. This allows attackers with lower privileges to potentially gain administrative access.

Another critical issue, CVE-2026-100673 (High, CVSSv3 8.2), affects the Grav Data Manager plugin (versions 1.0.1 through 1.4.4). This plugin renders stored data entries in the item-detail view without proper escaping. It applies Twig's raw filter, sometimes after a striptags('<br>') call, which PHP's strip_tags() can bypass. This can lead to stored cross-site scripting (XSS) attacks, where malicious scripts are embedded within the data and executed when viewed by other users.

The Comments plugin for Grav CMS is also impacted by CVE-2026-100672 (High, CVSSv3 7.5). Versions up to 1.2.10 register an admin handler that exposes comment data as JSON without an authentication check. The isAdmin() check is insufficient, as it only verifies the registration of the admin service on the current route, not the user's actual administrative privileges. This could allow unauthorized access to sensitive comment data.

Further vulnerabilities include CVE-2026-100671 (High, CVSSv3 8.0), which involves a Twig sandbox escape in page content rendering for specific versions of Grav CMS (2.0.19-2.0.24, and earlier versions with content Twig enabled). The sandbox allowslist includes get_cookie(), enabling attackers to retrieve any cookie sent with the request. Additionally, CVE-2026-100668 (Medium, CVSSv3 6.5) is a Twig content sandbox escape related to the array filter, which is registered without a necessary guard, potentially allowing for unintended code execution.

Configuration-related issues were also disclosed. CVE-2026-100669 (High, CVSSv3 7.5) points out that Grav's sample web server configurations (specifically webserver-configs/web.config for IIS) use case-sensitive deny rules. This could be exploited if attackers can manipulate case variations in URLs to bypass access controls for sensitive directories.

Finally, CVE-2026-100667 (Medium, CVSSv3 5.3) affects the Grav CMS Login plugin (versions >= 3.8.7 and < 3.9.7). It allows for a bypass of the two-factor authentication challenge for content protected by the authenticated() Twig function or [authenticated] shortcode. This occurs because the Login::isAuthenticated() check only verifies the session flag for 2FA, not the actual authentication status.

All affected Grav CMS versions should be updated to the latest available releases to mitigate these vulnerabilities. Users are advised to review their plugin configurations and apply any necessary patches or workarounds provided by the Grav CMS security team. The coordinated disclosure of these issues underscores the importance of timely patching and security audits for Grav CMS installations.

Synthesized by Vypr AI