Vulnerability Description
Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive directories outside GRAV_ROOT when not in the hard-coded deny-list. Attackers with profile editor access can configure backup profiles with traversal paths to expose sensitive files from locations like /opt, /mnt, or /srv.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/getgrav/grav/commit/ad9709f865b09b68798fb1ac375b484a8cc1d892
- https://github.com/getgrav/grav/security/advisories/GHSA-fch7-cpv4-w7hg
- https://www.vulncheck.com/advisories/grav-path-traversal-via-backup-profile-conf
- https://github.com/getgrav/grav/security/advisories/GHSA-fch7-cpv4-w7hg
FAQ
What is CVE-2026-72820?
CVE-2026-72820 is a vulnerability with a CVSS score of 4.9 (MEDIUM). Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive directories outside GRAV_ROOT when not in the hard-coded deny-list. Attackers with profil...
How severe is CVE-2026-72820?
CVE-2026-72820 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-72820?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.