
CVE-2026-42844 Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with http://api.media.write can abuse /api/v1/blueprint-upload to write an a… https://www.cve.org/CVERecord?id=CVE-2026-42844
Post summary
The post announces a new CVE for Grav 2.0.0-beta.2, detailing how a low-privileged authenticated user can write arbitrary data via the /api/v1/blueprint-upload endpoint.
