← back
CVE-2026-42607criticalCWE-94

Grav: Remote Code Execution (RCE) via Malicious Plugin ZIP Upload in Direct Install Feature

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.1epss 3.9%
from disclosure to weapon15 days
Published on NVDMay 11
1st PoC+15d
exploitation probability
3.9%top 11% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achieve Remote Code Execution (RCE) by uploading a specially crafted ZIP file through the "Direct Install" tool. While the system attempts to block direct .php file uploads, it fails to inspect the contents of uploaded ZIP archives. Once a malicious plugin is extracted, it can execute arbitrary PHP code or drop a persistent web shell on the server. This vulnerability is fixed in 2.0.0-beta.2.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected products
getgrav · grav
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.