CVE-2026-56700Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data without restricting allowed classes, enabling PHP object injection and, via a gadget chain, arbitrary code execution where an attacker controls the serialized input. Additionally, InstallCommand's git clone operation passes the branch, url, and path parameters into a shell command without escaping, allowing OS command injection via plugin/theme installation (which requires admin access). A Twig security blocklist bypass (server-side template injection) is also present. The issues are fixed in 2.0.0-beta.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-01: 2Patch / Workaround · 2026-07-01: 2Technical Details · 2026-07-01: 207-01
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Full discourse2 posts
  • Orizon@OrizonCyber
    Disclosure

    🚨 CVE-2026-56700 — CVSS 9.8/10 ██████████ Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/MTxt54I3UR

    Post summary

    CVE-2026-56700 is a critical code‑execution vulnerability in Grav CMS (pre‑2.0.0‑beta.2) due to unsafe unserialize() calls, with a patch now available.

    10000109
    63 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Grav CMS Multiple Remote Code Execution Vulnerabilities (CVE-2026-56700) Grav CMS ships several code-execution flaws. The headline issue is PHP object injection: three unsafe unserialize() calls (in Scheduler\JobQueue, FileCache, and Session) deserialize untrusted data without restricting allowed classes. Where an attacker controls the serialized input, a gadget chain turns that into arbitrary code execution — and the CVSS vector indicates no privileges or user interaction required. On top of that, the plugin/theme InstallCommand passes the branch, URL, and path into a git clone shell command without escaping, giving OS command injection (admin-only), and a Twig security blocklist bypass enables server-side template injection. 👉Upgrade to Grav 2.0.0-beta.2.

    Post summary

    The post alerts readers to multiple remote code‑execution vulnerabilities in Grav CMS, provides technical details, and recommends upgrading to Grav 2.0.0‑beta.2 to apply the fix.

    00000123
    232 followersView on X

Explore more