CVE-2026-85603
Last modified
CVE-2026-85603 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An authenticated admin user with admin.pages.create permission can supply directory traversal sequences in the lang POST field to write arbitrary .md files outside the pages directory with attacker-controlled content..
Description
Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An authenticated admin user with admin.pages.create permission can supply directory traversal sequences in the lang POST field to write arbitrary .md files outside the pages directory with attacker-controlled content.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| getgrav | grav | < 1.10.55 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-85603?
How severe is CVE-2026-85603?
How do I fix CVE-2026-85603?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-85598Grav versions 2.0.0 through 2.0.17 fail to apply save-time X…6.4
- CVE-2026-85599Grav Shortcode Core before 6.2.5 contains stored cross-site …7.2
- CVE-2026-8560Heap buffer overflow in SwiftShader in Google Chrome on Mac …4.3
- CVE-2026-85600Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 c…5.4
- CVE-2026-85601Grav Admin before 2.0.20 fails to sanitize output from marke…5.4
- CVE-2026-85602The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0…5.3
- CVE-2026-85604Grav before 2.0.18 (affected versions <= 2.0.17) contains a …8.8
- CVE-2026-85605Slink before 1.12.3 fails to properly authorize access to im…5.3
- CVE-2026-85606firecrawl-mcp-server 3.20.2 contains an arbitrary local file…7.5
- CVE-2026-85607Blinko 1.8.7 contains an authorization bypass (IDOR) vulnera…8.8
- CVE-2026-85608Douyin_TikTok_Download_API through 4.1.2 contains a server-s…7.5
- CVE-2026-85609Openpanel before 2.3.0 contains an unauthenticated full-read…7.5
Are you affected by CVE-2026-85603?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
