Arbitrary Method Invocation Vulnerability in Grav CMS by Getgrav
CVE-2026-69088

8.6HIGH

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
3 August 2026

What is CVE-2026-69088?

Versions 2.0.7 through 2.0.10 of Grav CMS have a vulnerability that allows an attacker with page-editing rights to exploit blueprint dynamic-field directives. The vulnerability arises because the method verification does not adequately restrict static method calls. This allows unauthorized access to invoke arbitrary public static PHP methods with manipulated arguments. By leveraging built-in gadget methods, an attacker may read sensitive files or create/copy files and directories under the web server's account. This vulnerability was patched in version 2.0.11.

Affected Version(s)

grav 2.0.7 < 2.0.11

grav 2.0.11

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

adamyordan
.