CVE-2026-42607Disclosure

MEDIUMCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achieve Remote Code Execution (RCE) by uploading a specially crafted ZIP file through the "Direct Install" tool. While the system attempts to block direct .php file uploads, it fails to inspect the contents of uploaded ZIP archives. Once a malicious plugin is extracted, it can execute arbitrary PHP code or drop a persistent web shell on the server. This vulnerability is fixed in 2.0.0-beta.2.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-05-11)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-10: 1Mentions · 2026-05-11: 3Active Exploitation · 2026-05-10: 1Patch / Workaround · 2026-05-10: 1Technical Details · 2026-05-10: 1Technical Details · 2026-05-11: 305-1005-11
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-101
Active Exploitation1
2026-05-113
Disclosure3
Full discourse4 posts
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Protect your Grav CMS deployments. Attackers are chaining CVE-2026-42613 and CVE-2026-42607 to achieve unauthenticated remote code execution. Patch today! #GravCMS #CyberSecurity #InfoSec #RCE #VulnerabilityAlert #ZeroDay #PatchNow #WebSecurity #CVE https://securityonline.info/grav-cms-critical-vulnerability-chain-cve-2026-42613-rce/ https://t.co/Oet9j3BQx1

    Post summary

    Grav CMS users are facing active exploitation of CVE-2026-42613 and CVE-2026-42607, enabling unauthenticated remote code execution; immediate patching is advised.

    2702562.0K
    12.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42607 Remote Code Execution in Grav via Malicious ZIP Upload Before 2.0.0-beta.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42607

    Post summary

    The text announces the discovery of a Remote Code Execution vulnerability in Grav, specifying the affected version and the exploitation vector, but does not mention exploitation details, patches, or active attacks.

    0000039
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42607 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achieve Remote Code Execution (RCE) by uploading a … https://www.cve.org/CVERecord?id=CVE-2026-42607 ----- Traducción: CVE-2026-42607 Gra… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-42607, a Web platform RCE vulnerability affecting authenticated admin users prior to 2.0.0-beta.2, but provides no PoC, exploit code, or patch information.

    0000029
    77 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42607 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achieve Remote Code Execution (RCE) by uploading a … https://www.cve.org/CVERecord?id=CVE-2026-42607

    Post summary

    The post provides a brief technical disclosure of a RCE flaw in Grav allowing authenticated admins to upload files, but offers no PoC, exploit, patch, or evidence of active exploitation.

    00000105
    57.5K followersView on X

Explore more