CVE-2026-75827: Grav before 2.0.15 Arbitrary File Write via error_log

Published Aug 18, 2026
·
Updated

Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config access can invoke the errorlog function through a data directive to append PHP payloads to web-accessible files, achieving remote code execution.

Affected Software

1 affected component
Grav Grav<2.0.15

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Grav to a version that resolves this vulnerability.

    Fixed in 2.0.15
  2. Compensating control

    If you cannot immediately upgrade past Grav before 2.0.15, restrict access so that attackers cannot obtain page-edit or blueprint-config permissions, since those access levels can invoke error_log via a data directive to write PHP payloads to web-accessible files.

Event History

Aug 18, 2026
CVE Published
via MITRE·11:19 AM
Data Sourced
via MITRE·11:19 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What level of access does an attacker need to exploit this issue?

An attacker must already have page-edit or blueprint-configuration access. The vulnerable dynamic-data handling can then be used to invoke error_log and append a PHP payload to a web-accessible file.

2

What can an attacker do after successful exploitation?

The described impact is remote code execution after the attacker writes a PHP payload into a web-accessible file. Exploitation does not require user interaction.

3

Which versions need to be remediated?

Upgrade Grav to 2.0.15 or later. The affected versions are Grav releases before 2.0.15.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203