kokumօtօ[verified]@__kokumotoDisclosure
The post announces the disclosure of a chained vulnerability in Grav CMS, detailing CVE‑2026‑42613 (self‑admin via user registration) and CVE‑2026‑42607 (RCE via Direct Install). No exploit code, active exploitation, or patch information is provided.
Gray Hats@the_yellow_fallActive Exploitation
Attackers are actively exploiting two chained CVEs in Grav CMS to gain unauthenticated remote code execution; users are advised to patch immediately.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A new privilege escalation vulnerability (CVE‑2026‑42613) has been disclosed for Grav Login Plugin versions before 2.0.0‑beta.2, with no evidence of PoC, exploit, or patch information yet.
CVE@CVEnewDisclosure
The tweet discloses that a flaw in Grav’s Login::register() method (before 2.0.0-beta.2) allows attacker-controlled group and access fields, indicating a potential privilege escalation vulnerability.
Baikuya@Baikuya3Disclosure
The user reports a newly disclosed CVE-2026-42613 in Grav CMS that may allow unauthenticated remote code execution, referencing the official advisory but providing no exploit code, patch info, or evidence of active exploitation.