CVE-2026-72827: Grav CMS before 2.0.13 Remote Code Execution via Twig
Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands. Attackers can inject Twig payloads using the unsandboxed find filter in email subject, body, to, or from fields to achieve remote code execution when forms are submitted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72827?
CVE-2026-72827 has a severity rating of 8.8, indicating a high risk of exploitation.
How do I fix CVE-2026-72827?
To mitigate CVE-2026-72827, upgrade Grav CMS to version 2.0.13 or later.
What does CVE-2026-72827 affect?
CVE-2026-72827 affects all versions of Grav CMS prior to 2.0.13.
What type of vulnerability is CVE-2026-72827?
CVE-2026-72827 is a remote code execution vulnerability due to server-side template injection.
Who can exploit CVE-2026-72827?
CVE-2026-72827 can be exploited by low-privileged page editors, allowing them to execute arbitrary commands.