Input validation error in Grav CMS - CVE-2026-42613

 

Input validation error in Grav CMS - CVE-2026-42613

Published: May 5, 2026


Vulnerability identifier: #VU130076
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-42613
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper input validation in the Login::register() method in the Login plugin when handling registration POST data. A remote attacker can submit crafted groups or access fields in a registration request to escalate privileges.

Exploitation requires registration to be enabled and the groups or access fields to be included in the configured allowed fields list.


Affected software

Grav CMS

How to mitigate CVE-2026-42613

Install security update from vendor's website.

Grav CMS - update to 2.0.0 beta.2

External References

Related Security Bulletins