No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 27 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile() that allows local attackers to overwrite arbitrary files by pre-creating symlinks at predictable lock file paths in the world-writable temp directory. Attackers can place a symlink at the predictable lock path pointing to any file the web server process can write to, and the next scheduled job run will follow the symlink and overwrite the target file's content with the job ID string. | |
| Title | Grav CMS before 2.0.16 Symlink Following via createLockFile | |
| First Time appeared |
Getgrav
Getgrav grav |
|
| Weaknesses | CWE-59 | |
| CPEs | cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Getgrav
Getgrav grav |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-27T14:52:18.096Z
Reserved: 2026-08-10T13:02:20.828Z
Link: CVE-2026-72696
Updated: 2026-08-27T14:51:55.076Z
Status : Received
Published: 2026-08-25T02:16:45.253
Modified: 2026-08-27T17:19:50.293
Link: CVE-2026-72696
No data.
OpenCVE Enrichment
Updated: 2026-08-25T03:45:05Z