PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72827 getgrav CVE debrief

CVE-2026-72827 is a server-side template injection vulnerability in Grav CMS before version 2.0.13. The vulnerability allows low-privileged page editors to execute arbitrary operating-system commands via email-action parameters. Attackers can inject Twig payloads in email fields to achieve remote code execution when forms are submitted. This vulnerability has a high severity score and requires immediate attention from defenders responsible for Grav CMS installations. They should assess exposure and apply patches or mitigations to prevent remote code execution.

Vendor
getgrav
Product
grav
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-14
Original CVE updated
2026-09-08
Advisory published
2026-08-14
Advisory updated
2026-09-08

Who should care

Defenders responsible for Grav CMS installations, particularly those with low-privileged page editors, should assess exposure and apply patches or mitigations to prevent remote code execution.

Why it matters

CVE-2026-72827 is a high-severity vulnerability in Grav CMS that allows remote code execution via server-side template injection. Defenders should prioritize verifying exposure and applying patches or mitigations to prevent exploitation.

  • Remote code execution via email-action parameters
  • Potential for arbitrary operating-system command execution
  • Exposure of Grav CMS installations to low-privileged page editors
  • Verification of patch application and vulnerability mitigation

Technical summary

The vulnerability is caused by unsandboxed use of the find filter in email subject, body, to, or from fields, allowing low-privileged page editors to inject Twig payloads and execute arbitrary operating-system commands. This occurs in Grav CMS before version 2.0.13. The vulnerability allows remote code execution when forms are submitted. Defenders should prioritize verifying exposure and applying patches or mitigations, as the vulnerability allows remote code execution with a high severity score of 8.7. The CVE record and NVD entry provide details on the vulnerability.

Defensive priority

Defenders should prioritize verifying exposure and applying patches or mitigations, as the vulnerability allows remote code execution.

Recommended defensive actions

  • Verify Grav CMS version and apply patch to version 2.0.13 or later
  • Restrict access to email-action parameters for low-privileged page editors
  • Monitor for suspicious email activity and Twig payload injections
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Review compensating controls for exposed systems while remediation is scheduled and verified

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but vendor-provided patches or additional information are not available in the corpus. The vulnerability was disclosed on 2026-08-14 and has not been modified since then. The CVE Program record and NVD detail page offer source-provided CVE metadata and official vulnerability assessment. However, defenders should verify the affected scope, severity, and vendor guidance through official advisories or CVE records.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72827 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72827

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72827 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72827

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.