OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100672

HIGH · CVSS 7.5 EPSS 0.45% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The Comments plugin for Grav CMS versions up to 1.2.10 is vulnerable due to a lack of authentication checks, allowing unauthenticated attackers to retrieve recent comments, including sensitive information such as email addresses and server file paths. This vulnerability poses a high risk to sites using the classic Admin plugin with Comments enabled, as it can lead to data exposure. Administrators of affected Grav CMS installations should prioritize upgrading to version 1.2.11 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100672
Severity
HIGH
CVSS
7.5
EPSS
0.45%

Original NVD Description

The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that returns comment data as JSON without any authentication check. The handler branches on isAdmin(), which only indicates that the admin service is registered on the current route rather than that the visitor is authenticated, and it echoes the JSON and calls exit() during the plugins stage, before the classic Admin plugin would render its login screen. On a site using the classic Admin plugin with Comments enabled (the default), an unauthenticated remote attacker can request /admin/comments/page:<n> (e.g. page:0.001) and retrieve every comment from the last 7 days, including each commenter's email address and the absolute server filesystem path of the data file. Sites running the Grav 2.0 Admin Next stack (admin2 + api) are not affected via this path. The issue is fixed in 1.2.11, which requires an authenticated user with admin.comments or admin.super and removes the absolute filePath from the response.