Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-75827 — Proof-of-concept and lab for CVE-2026-75827, a Grav arbitrary file write via Blueprint dynamic-data error_log, with reproduction script and Docker lab. | Kitploit
도구/GitHubGitHub/abraxas/cve-2026-75827
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingLearning & EducationLabs & Practice
GitHubabraxas/cve-2026-75827

CVE-2026-75827

Proof-of-concept and lab for CVE-2026-75827, a Grav arbitrary file write via Blueprint dynamic-data error_log, with reproduction script and Docker lab.

저장소 보기
218일 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

Abraxas Labs - CVE-2026-75827

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-75827

CVE-2026-75827

Grav 2.0.13 - getgrav

I am @abraxas_null. Loopback lab. The client is CVE-2026-75827-Abraxas-Labs.py.

The denylist missed error_log. Grav through 2.0.14 allowlists Class::method dynamic-data providers and denylists bare functions. A page-edit account plants a Form blueprint data-options@ directive. GET of that public form runs call_user_func_array on a bare PHP function. error_log type 3 appends attacker bytes to an attacker path. Then GET the file. Confirmed on tag 2.0.13. Patched in 2.0.15. This is not an upload action=.

CVECVE-2026-75827 · CVE.org
CWECWE-94
CVSSHigh: 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ProductGrav
Affectedall versions through 2.0.13 (inclusive)
Patched2.0.15 and later
Authauthenticated (page-edit)
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Someone with page-edit or blueprint-config plants data-options@: ['error_log', payload, 3, web-path]. A later GET of that form appends the payload. Point the path at a web-accessible .php and it is RCE. The lab stops at a unique string in poc-witness.txt. It is not unauthenticated RCE from a cold site.


How I found it

The GHSA named the denylist hole. I read isSafeDynamicCall, then Utils::isDangerousFunction, then the Form page. error_log is not on the list. The Class::method half already used a positive allowlist after GHSA-7pgq. The bare-function half did not.

Plant, then GET. The fixture page is already in the lab tree. GET /poc-form. Grav builds the form, hits dynamicData, calls error_log. Then GET /poc-witness.txt. Unique string, not a homepage, not a 404. Multiple GETs of the form append.

Wrong turns that already cost time: treating this as an upload action=; treating the form 200 as the proof (still Grav theme); treating Composer yelling about PHP 8.2 as a miss (the write still landed); putting system() in the message. The second GET is the tell.


The lab

Port 8088. Grav 2.0.13 admin skeleton, Form plugin on, web root writable. PHP 8.2 image is fine; Composer will complain.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml
  • lab/php-lab.ini

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-75827-Abraxas-Labs.py

Witness: GET /poc-witness.txt body contains POCWitness75827. Home HTML or empty 404 is not it.

Ways to lose without learning anything:

  • generic 200 Grav home HTML without the witness file
  • 404 poc-witness.txt
  • reverse shell or outbound connect
  • system() / exec() PHP payload

The fix

Update Grav to 2.0.15 or newer. Re-run CVE-2026-75827-Abraxas-Labs.py against the patched build: POCWitness75827 must not appear.


References

  • CVE-2026-75827 · NVD

  • CVE-2026-75827 · CVE.org

  • github.com/getgrav/grav/security/advisories/GHSA-f8wv-xp27-6gq7

  • www.vulncheck.com/advisories/grav-before-arbitrary-file-write-via-error-log

  • github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75827.json

  • nvd.nist.gov/vuln/detail/CVE-2026-75827

  • github.com/advisories/GHSA-f8wv-xp27-6gq7

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

도구 다운로드