CVE-2026-62673: Getgrav Grav

High severity, CVSS 8.2. EPSS: 0.5% chance of exploitation in the next 30 days.

Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess.txt security rules omit the Apache [NC] flag and therefore compare sensitive directory and file-extension patterns case-sensitively. On a case-insensitive filesystem, an unauthenticated requester can use uppercase directory or extension variants to bypass the rules and retrieve files under user/accounts or user/config, including password hashes and security configuration. This issue is fixed in version 2.0.4.

Affected products

  • Getgrav Grav: before 2.0.4 (fixed in 2.0.4)

Published 2026-08-19. Last modified 2026-09-09.