Junglewise Threat Intelligence

CVE-2026-62230: Grav .htaccess security bypass via case variation

CVE-2026-62230 · Severity: high · CVSS 7.5 · Published 2026-07-17

Technologies: Grav, Getgrav Grav, getgrav/grav (Packagist). Vendors: Grav, Getgrav, Packagist.

Executive brief

Grav, a popular open-source content management system, contains a security flaw in its default web server configuration. When Grav is hosted on systems that do not distinguish between uppercase and lowercase filenames (such as Windows or macOS), an attacker can bypass security restrictions to download sensitive files. This could lead to the exposure of API keys, database credentials, and website source code, potentially allowing for full site compromise.

Technical details

A vulnerability exists in the default .htaccess and webserver-configs/htaccess.txt files provided with Grav. The RewriteRule directives intended to block access to sensitive directories (system/, vendor/, and user/) and file extensions (.yaml, .php, .json, etc.) lack the [NC] (No Case) flag. On case-insensitive filesystems like NTFS (Windows) or HFS+ (macOS), the underlying OS will serve a file even if the request uses different casing, but the Apache mod_rewrite rules will fail to match and block the request. An unauthenticated remote attacker can exploit this by requesting files like 'config.YAML' or 'index.PHP' to bypass the blocklist and exfiltrate sensitive credentials or source code. The issue is resolved in version 2.0.4 by adding the [NC] flag to the affected rules.

Affected products

  • getgrav Grav < 2.0.4

Timeline

  • 2026-06-29: advisory: Initial GitHub Security Advisory published
  • 2026-07-16: disclosed: CVE published to NVD and VulnCheck advisory released
  • 2026-07-17: patched: Fix confirmed available in version 2.0.4

References

Related threats