Vulnary
← back to the feed
Critical· 9.3official fix available

CVE-2026-65008

Grav CMS version 2.0.4 contains a remote code execution flaw in Blueprint::dynamicData() that lets an authenticated user with admin.pages or api.pages.write permission inject a malicious callable into a page's frontmatter. When any visitor (even unauthenticated) views the page, the injected code runs as the web‑server user. The issue is fixed in Grav 2.0.7.

publishedJul 21, 2026
last modifiedJul 22, 2026
sourcesNVD
severity · cvss
9.3
critical · how bad it is
exploitation · epss
<1%
54th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 20, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Grav 2.0.4

02

Real-world impact

An attacker with limited admin privileges can achieve full remote code execution on the server, potentially compromising the entire site.

03

Why this severity

CVSS v4.0 base score 9.3 (Critical) reflects network‑adjacent, low‑complexity attack requiring no user interaction and high impact on confidentiality, integrity, and availability.

04

What to do about it

official fix available
recommended steps
  1. 011. Upgrade Grav to version 2.0.7 or later.
  2. 022. After upgrading, verify the version number in the admin dashboard or via command line.
  3. 033. Restart the web server if required: No additional steps are specified by the vendor; a service restart is not mandatory but may be advisable to ensure the new code is loaded.

NVD-referenced vendor advisory (fixed in 2.0.7)

05

Timeline

  1. Jul 21, 2026 · 12d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 21, 2026 · 12d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Attack requirementsNone
Privileges requiredNone
User interactionNone needed
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →