CVE-2026-42607 EXPLOIT
9.1
CRITICAL · CVSS 3.1 · EPSS 2.3% (pctl 82)
Patch early
A public exploit exists.
Description
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achieve Remote Code Execution (RCE) by uploading a specially crafted ZIP file through the "Direct Install" tool. While the system attempts to block direct .php file uploads, it fails to inspect the contents of uploaded ZIP archives. Once a malicious plugin is extracted, it can execute arbitrary PHP code or drop a persistent web shell on the server. This vulnerability is fixed in 2.0.0-beta.2.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 2.25% — more likely to be exploited than 82% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2026-05-11 |
| Last modified | 2026-06-17 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Grav CMS 2.0.0-beta.2 - Remote Code Execution | 2026-05-26 |
References
→ the Explorer · watch your stack · NVD