Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile() that allows local attackers to overwrite arbitrary files by pre-creating symlinks at predictable lock file paths in the world-writable temp directory. Attackers can place a symlink at the predictable lock path pointing to any file the web server process can write to, and the next scheduled job run will follow the symlink and overwrite the target file's content with the job ID string. | |
| Title | Grav CMS before 2.0.16 Symlink Following via createLockFile | |
| First Time appeared |
Getgrav
Getgrav grav |
|
| Weaknesses | CWE-59 | |
| CPEs | cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Getgrav
Getgrav grav |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T01:30:14.848Z
Reserved: 2026-08-10T13:02:20.828Z
Link: CVE-2026-72696
No data.
Status : Received
Published: 2026-08-25T02:16:45.253
Modified: 2026-08-25T02:16:45.253
Link: CVE-2026-72696
No data.
OpenCVE Enrichment
Updated: 2026-08-25T03:45:05Z
-
CWE-59
Improper Link Resolution Before File Access ('Link Following')