CVE-2026-42608Active Exploitation(getgrav / grav)

MEDIUMCVSS 9.1 · CRITICAL

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch getgrav grav systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulating the session_id (passed as __form-flash-id in POST requests), an unauthenticated attacker can traverse the filesystem to create arbitrary directories and write an index.yaml file containing attacker-controlled data. This vulnerability can lead to unauthorized modification of application behavior, potential data integrity issues, and service disruption in production environments. This vulnerability is fixed in 2.0.0-beta.2.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • grav

Threat summary

  • Active exploitation appears in 6 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 5 observed days

What's happening

  • Active exploitation reported across 6 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 11 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 5 mentions (2026-09-26); latest day: 1
  • 12 total mentions across 5 days

Affected systems

Vendors
Products
grav

1 version affected across 1 product

Deep dive

Activity timeline12 mentions / 5d
01345Mentions · 2026-05-11: 3Mentions · 2026-05-15: 1Mentions · 2026-09-25: 2Mentions · 2026-09-26: 5Mentions · 2026-10-01: 1PoC Mentioned / Linked · 2026-09-26: 1Active Exploitation · 2026-09-25: 2Active Exploitation · 2026-09-26: 4Patch / Workaround · 2026-05-15: 1Patch / Workaround · 2026-09-25: 1Patch / Workaround · 2026-09-26: 5Technical Details · 2026-05-11: 3Technical Details · 2026-05-15: 1Technical Details · 2026-09-25: 2Technical Details · 2026-09-26: 505-1105-1509-2509-2610-01
Signal classification3 categories
Active Exploitation
654.5%
Disclosure
327.3%
Patch
218.2%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-05-113
Disclosure3
2026-05-151
Patch1
2026-09-252
Active Exploitation2
2026-09-265
Active Exploitation4Patch1
Full discourse12 posts
  • Juan F Gallego@jfernandogg
    Active Exploitation

    El sitio Tor donde Clop publica víctimas fue alterado y comprometido. ShinyHunters explotó un path traversal en Grav CMS (CVE-2026-42608) en la 1.7.43 y dice haber robado plugins, logs y keys del onion. Grav confirmó el bug a BleepingComputer y backportó el fix a 1.7.53.4 (en 2.x ya estaba). La ironía sirve: hasta los grupos de ransomware dejan software sin parchar. Clop admite que no había actualizado Grav del todo. Si tienes Grav —o cualquier CMS "tranquilo"— en internet, la versión importa más que la reputación del sitio. 1.7.53.4 o migra a 2.x. El software que nadie mira es el que más se atrasa.

    Post summary

    ShinyHunters claim to have actively exploited CVE-2026-42608 in Grav CMS 1.7.43, and Grav has released a patch (1.7.53.4) urging users to upgrade.

    00011204
    345 followersView on X
  • z3n@zench4n
    Patch

    Summary: Patch your orchestration layers, audit your agent dependencies, and monitor for path traversal risks like CVE-2026-42608. Security for agents isn't just about the prompt; it's about the integrity of the entire execution environment.

    Post summary

    The advisory urges patching orchestration layers and monitoring for path traversal vulnerabilities such as CVE-2026-42608.

    000109
    1.4K followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: High CVE: CVE-2026-42608 Product: getgrav / grav Summary: VulnCheck reports real-world exploitation activity affecting getgrav / grav. Evidence: Active exploitation reported; Severe impact class Impact: The vulnerability has a severe impact class such as code execution, authentication bypass, account takeover, or privilege escalation. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 25 Sep 2026 Source: https://vulncheck.com/ #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #getgrav #grav #CVE_2026_42608 #ActiveExploitation #Exploit

    0000049
    226 followersView on X
  • P.K. Sharma@_pksharma
    Patch

    Grav CMS advisory for CVE-2026-42608 lists exactly one fixed version: 2.0.0-beta.2. Everybody runs 1.7. For five months, the remedy on offer to them was a pre-release of a major upgrade. 🧷 Unauthenticated path traversal in the FormFlash component, through the `__form-flash-id` parameter. 8.8 under CVSS v4.0, with exploit maturity recorded in the vector as proof of concept. Affected range 0.8.0 through 2.0.0-beta.1. Advisory published 27 April 2026. Machine-readable record on 5 May. ⚖️ On 18 September, 144 days later, the Clop ransomware group's leak site was defaced. It was running Grav 1.7.43. Grav shipped 1.7.53.4 with the backport the following day. The backport existed. It just had not been released, and nothing in the advisory said one was coming. 🧮 1.7.43 also predates 1.7.45, which fixed a separate path traversal, CVE-2024-27921, in March 2024. So the leak site was behind on two. ShinyHunters claimed source code, plugins, server logs and the Tor onion private keys. 🔍 What this does not establish: not which flaw was used, because nobody has said. Not that the maintainers did anything improper, because listing the branch you fixed is honest. 🔑 The practical point is about how you read a fixed-version field. A range that ends in a beta is not a patch instruction for a production branch. It is a statement about a different branch, and the difference is five months wide. Full briefing: https://www.pk-sharma.com/briefing/the-only-fix-was-a-beta #InfoSec #CyberSecurity #Vulnerability #PatchManagement #CVE #ThreatIntel #AppSec #Ransomware #CISO #RiskManagement #BlueTeam #SecOps #OpenSource #UKTech

    Post summary

    The advisory for CVE‑2026‑42608 initially listed only a beta version as the fix, but a production backport (1.7.53.4) was later released, highlighting the need to correctly interpret fixed‑version fields. The vulnerability is an unauthenticated path traversal in Grav’s FormFlash component with CVSS 8.8, though no PoC or confirmed exploitation is reported.

    00000173
    191 followersView on X
  • Arnaud Wallon@arwallon
    Active Exploitation

    🚨 La faille #Grav CMS (CVE-2026-42608) qui a coulé le site de #Clop est confirmée ! ShinyHunters avait raison : une faille path traversal dans Grav 1.7 a permis de pirater le serveur du gang. Le correctif (1.7.53.4) arrive… enfin. 🔗 Mettez à jour URGEMMENT si vous utilisez Grav 1.7 ! #Cybersécurité #Ransomware https://numeribrain.com/posts/grav-cms-faille-cve-2026-42608-clop-correctif

    Post summary

    The tweet confirms that CVE-2026-42608, a path traversal flaw in Grav CMS 1.7, was exploited to compromise the Clop ransomware group's site, notes that a patch (version 1.7.53.4) is forthcoming, and urges immediate updates.

    00000251
    364 followersView on X
  • NEXSIGHT@NEXSIGHTNEWS
    Active Exploitation

    Gravが旧版1.7系に緊急修正「1.7.53.4」を公開 — 認証なしでファイルを書き込める欠陥CVE-2026-42608を逆移植、ランサム集団Clopへの侵入に悪用 https://cyber.nexsight.co/articles/2026/09/26/grav-cve-2026-42608-1-7-53-4-backport-clop-shinyhunters-2026-09-26/

    Post summary

    The text reports that Grav CMS released emergency backport fix version 1.7.53.4 for CVE-2026-42608, an unauthenticated file-write vulnerability that has been actively exploited in the wild by the Clop ransomware group.

    0000065
    76 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    ShinyHunters defaced Clop's leak site via an unauthenticated Grav CMS path traversal flaw, forcing a Tor move. Grav confirmed CVE-2026-42608 and patched the 1.7 branch in 1.7.53.4. #Clop #ShinyHunters #Grav https://www.hendryadrian.com/shinyhunters-hacked-clop-leak-site-using-grav-cms-path-traversal-flaw/

    Post summary

    ShinyHunters exploited an unauthenticated path traversal flaw in Grav CMS to deface Clop's leak site, prompting a Tor migration; Grav confirmed CVE-2026-42608 and patched via version 1.7.53.4.

    00000520
    4.9K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    ShinyHunters exploited CVE-2026-42608 to breach Clop's own ransomware leak site, using path traversal to upload malicious files and steal Tor private keys. Attackers moved laterally through the compromised Grav CMS to access sensitive operational data. Runtime segmentation could have limited blast radius of this multi-stage breach. #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/shinyhunters-hacked-clop-leak-site-grav-cms-cve-2026-42608

    Post summary

    The tweet reports that actor ShinyHunters actively exploited CVE-2026-42608 (path traversal) to breach Clop's infrastructure, providing technical details on the attack vector while confirming in-the-wild usage without linking PoC code or a vendor patch.

    00000132
    2.0K followersView on X
  • Anthony Bahn@HoustonIntrove1
    Active Exploitation

    Even Clop left Grav 1.7 unpatched long enough for ShinyHunters to path-traverse the leak site and deface it. CVE-2026-42608. The 1.7 backport just landed as 1.7.53.4. I'm checking every Grav box we still have before Monday.

    Post summary

    The post reports that CVE-2026-42608, a path traversal vulnerability in Grav, was actively exploited by ShinyHunters to deface a site, and notes that a patched version (1.7.53.4) has been released.

    0000053
    42 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42608 Path Traversal in Grav FormFlash Component Prior to 2.0.0-beta.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42608

    Post summary

    The post announces a path traversal vulnerability (CVE-2026-42608) affecting Grav FormFlash Component before version 2.0.0‑beta.2, without providing PoC, exploit, or patch details.

    0000036
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42608 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulating the session_id … https://www.cve.org/CVERecord?id=CVE-2026-42608 ----- Traducción: CVE-2026-42608 Gra… http://infoflow.cloud`

    Post summary

    Announces CVE‑2026‑42608, a Path Traversal flaw in Grav’s FormFlash component affecting versions before 2.0.0‑beta.2, with a link to the official CVE record for details.

    0000028
    77 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42608 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulating the session_id … https://www.cve.org/CVERecord?id=CVE-2026-42608

    Post summary

    The passage announces a path traversal flaw in Grav’s FormFlash component (CVE-2026-42608) affecting versions before 2.0.0-beta.2, describing the affected component and the manipulation technique.

    00000106
    57.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgetgravgrav---
Appgetgravgrav2.0.0--

Explore more