CVE-2026-72820

Source
https://cve.org/CVERecord?id=CVE-2026-72820
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72820.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72820
Aliases
  • GHSA-fch7-cpv4-w7hg
Published
2026-08-14T11:35:30.155Z
Modified
2026-08-16T03:48:48.300393374Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Grav 2.0.11 Path Traversal via Backup Profile Configuration
Details

Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive directories outside GRAV_ROOT when not in the hard-coded deny-list. Attackers with profile editor access can configure backup profiles with traversal paths to expose sensitive files from locations like /opt, /mnt, or /srv.

Database specific
{
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72820.json",
    "cwe_ids": [
        "CWE-22"
    ]
}
References

Affected packages

Git / github.com/getgrav/grav

Affected ranges

Type
GIT
Repo
https://github.com/getgrav/grav
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.0.11"
        },
        {
            "fixed": "2.0.13"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

2.*
2.0.11
2.0.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72820.json"