Remote Code Execution in Grav Email Plugin by Grav
CVE-2026-75574

8.7HIGH

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-75574?

The Grav Email plugin prior to version 4.2.2 has a critical flaw that enables an authenticated remote user, possessing only api.access and api.pages.write permissions, to manipulate Email action parameters. The flaw allows the insertion of a Twig expression into the header.form.process.email.body, leading to execution of arbitrary operating-system commands on the server, thereby compromising the security of the application.

Affected Version(s)

grav 0 < 4.2.2

grav 4.2.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0tra4e
.