Case Sensitivity Vulnerability in Grav Web Platform
CVE-2026-62673
What is CVE-2026-62673?
Grav, a file-based web platform, has a vulnerability in its security configuration that affects versions prior to 2.0.4. The .htaccess and webserver-configs/htaccess.txt rules do not include the Apache [NC] flag, leading to case-sensitive comparisons of sensitive directory and file-extension patterns. This flaw enables an unauthenticated user to exploit case variations in directory names or file extensions, potentially bypassing security measures. As a result, attackers could gain unauthorized access to sensitive files, including user accounts and configurations, leading to the exposure of password hashes and sensitive security settings. The issue was remedied in version 2.0.4, highlighting the importance of keeping software updated to mitigate security risks.
Affected Version(s)
grav < 2.0.4
