CVE-2026-72820: Grav 2.0.11 Path Traversal via Backup Profile Configuration
Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive directories outside GRAVROOT when not in the hard-coded deny-list. Attackers with profile editor access can configure backup profiles with traversal paths to expose sensitive files from locations like /opt, /mnt, or /srv.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
gravto a version that resolves this vulnerability.Fixed in 2.0.13 - Upgrade
Upgrade
gravto a version that resolves this vulnerability.Patch Grav 2.0.11 Path Traversal via Backup Profile Configuration
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72820?
The severity of CVE-2026-72820 is classified as medium with a score of 4.9.
How do I fix CVE-2026-72820?
To fix CVE-2026-72820, upgrade Grav to version 2.0.13 or later.
What type of vulnerability is CVE-2026-72820?
CVE-2026-72820 is a Path Traversal vulnerability.
What can attackers do with CVE-2026-72820?
Attackers with profile editor access can configure backup profiles that expose sensitive files from directories outside GRAV_ROOT.
Which versions of Grav are affected by CVE-2026-72820?
Grav versions before 2.0.13 are affected by CVE-2026-72820.