CVE-2026-42613Disclosure

MEDIUMCVSS 9.4 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attacker-controlled groups and access fields from the registration POST data without server-side validation. When registration is enabled and groups or access are included in the configured allowed fields list, an unauthenticated user can self-register with admin.super privileges by injecting these fields into the registration request. This vulnerability is fixed in 2.0.0-beta.2.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-862

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-10); latest day: 2
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-05-08: 1Mentions · 2026-05-10: 2Mentions · 2026-05-11: 2PoC Mentioned / Linked · 2026-05-10: 1Active Exploitation · 2026-05-10: 1Patch / Workaround · 2026-05-10: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-10: 2Technical Details · 2026-05-11: 205-0805-1005-11
Signal classification2 categories
Disclosure
480.0%
Active Exploitation
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-081
Disclosure1
2026-05-102
Active Exploitation1Disclosure1
2026-05-112
Disclosure2
Full discourse5 posts
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Protect your Grav CMS deployments. Attackers are chaining CVE-2026-42613 and CVE-2026-42607 to achieve unauthenticated remote code execution. Patch today! #GravCMS #CyberSecurity #InfoSec #RCE #VulnerabilityAlert #ZeroDay #PatchNow #WebSecurity #CVE https://securityonline.info/grav-cms-critical-vulnerability-chain-cve-2026-42613-rce/ https://t.co/Oet9j3BQx1

    Post summary

    Attackers are actively exploiting two chained CVEs in Grav CMS to gain unauthenticated remote code execution; users are advised to patch immediately.

    2702562.0K
    12.5K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    Grav CMSを無認証で乗っ取れる脆弱性攻撃が開示された。ユーザー登録時に自分で管理者になれるCVE-2026-42613とDirect Install機能での遠隔コード実行CVE-2026-42607を連鎖させるもの。前者はユーザー登録が有効化されており、グループかアクセスが設定可能なことが条件。 https://securityonline.info/grav-cms-critical-vulnerability-chain-cve-2026-42613-rce/

    Post summary

    The post announces the disclosure of a chained vulnerability in Grav CMS, detailing CVE‑2026‑42613 (self‑admin via user registration) and CVE‑2026‑42607 (RCE via Direct Install). No exploit code, active exploitation, or patch information is provided.

    010521.3K
    7.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42613 Privilege Escalation in Grav Login Plugin Prior to 2.0.0-beta.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42613

    Post summary

    A new privilege escalation vulnerability (CVE‑2026‑42613) has been disclosed for Grav Login Plugin versions before 2.0.0‑beta.2, with no evidence of PoC, exploit, or patch information yet.

    0000048
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42613 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attacker-controlled groups and access fields from t… https://www.cve.org/CVERecord?id=CVE-2026-42613

    Post summary

    The tweet discloses that a flaw in Grav’s Login::register() method (before 2.0.0-beta.2) allows attacker-controlled group and access fields, indicating a potential privilege escalation vulnerability.

    00000106
    57.5K followersView on X
  • Baikuya@Baikuya3
    Disclosure

    I did some research in Grav CMS. Obviously I also used AI, but Claude missed this bug: https://github.com/getgrav/grav/security/advisories/GHSA-pxm6-mhxr-q4mj This is now CVE-2026-42613, which may lead to unauthenticated RCE. But Claude found some really nice SSTI chains that also lead to RCE, but this is not public yet. :)

    Post summary

    The user reports a newly disclosed CVE-2026-42613 in Grav CMS that may allow unauthenticated remote code execution, referencing the official advisory but providing no exploit code, patch info, or evidence of active exploitation.

    0000066
    98 followersView on X

Explore more