PatchSiren cyber security CVE debrief
CVE-2026-75574 getgrav CVE debrief
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsandboxed Twig templates. An authenticated remote user with only api.access and api.pages.write permissions can place a Twig expression in header.form.process.email.body, publish the page, and submit the form to execute an arbitrary operating-system command as the account running PHP. This vulnerability affects users of the Grav Email plugin, especially those with api.access and api.pages.write permissions. The CVE record was published on 2026-08-25T02:16:51.303Z and has not been modified since then. Users should verify their plugin version and configuration.
- Vendor
- getgrav
- Product
- grav
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-25
- Original CVE updated
- 2026-08-31
- Advisory published
- 2026-08-25
- Advisory updated
- 2026-08-31
Who should care
Users of the Grav Email plugin, especially those with api.access and api.pages.write permissions, should verify their plugin version and configuration. Affected operators and platforms should review compensating controls and implement monitoring and exception tracking. Security teams should prioritize patching and vulnerability management for this plugin. System administrators and developers using the Grav Email plugin should also be aware of the potential risks and take necessary precautions. Additionally, vulnerability management teams should assess the impact of this vulnerability on their systems and plan accordingly. Security teams should also review the CVE record and vendor guidance for further information. IT teams responsible for maintaining Grav installations should ensure they have the latest version of the Email plugin. Those with limited permissions may still be at risk if they can publish pages or submit forms. The vulnerability's impact on various platforms and the need for compensating controls should be evaluated. Security teams should also consider implementing additional monitoring and logging to detect potential exploitation attempts. Overall, a broad range of stakeholders, from developers to security teams and system administrators, should be aware of this vulnerability and take appropriate actions to mitigate its risks. The vulnerability management process should include verifying plugin versions, restricting permissions, and applying compensating controls where necessary. Effective communication between security teams, system administrators, and developers is crucial to address this vulnerability effectively. The CVE record provides essential information for understanding the vulnerability's severity and scope, and it should be reviewed in conjunction with vendor guidance and other relevant sources. By taking a proactive and informed approach, organizations can minimize the risks associated with this vulnerability and protect their systems from potential exploitation. The CVE record and vendor guidance should be consulted for further details on affected versions, patches, and mitigation strategies. Security teams and system administrators
Technical summary
The Grav Email plugin before 4.2.2 renders page-editor-controlled Email action parameters as unsandboxed Twig templates. An authenticated remote user with only api.access and api.pages.write permissions can place a Twig expression in header.form.process.email.body, publish the page, and submit the form to execute an arbitrary operating-system command as the account running PHP. This vulnerability allows for potential code execution and system compromise.
Defensive priority
Authenticated remote users with limited permissions can execute arbitrary operating-system commands as the PHP account.
Recommended defensive actions
- Inventory and verify the Grav Email plugin version and configuration.
- Restrict api.access and api.pages.write permissions to trusted users.
- Implement compensating controls, such as monitoring and exception tracking.
- Apply the vendor remediation when available.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The Grav Email plugin before 4.2.2 renders page-editor-controlled Email action parameters as unsandboxed Twig templates. An authenticated remote user with only api.access and api.pages.write permissions can place a Twig expression in header.form.process.email.body, publish the page, and submit the form to execute an arbitrary operating-system command as the account running PHP.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75574 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75574
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75574 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75574
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/getgrav/grav/security/advisories/GHSA-gh8j-q67c-j53f
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/grav-before-remote-code-execution-via-email-twig
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.