SCA: security update for getgrav/grav (GHSA-rr73-568v-28f8)

high Tenable Cloud Security Plugin ID 441199

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin
Panel allows a low-privileged user (with only user creation permissions) to overwrite existing accounts,
including the primary administrator. By creating a new user with a username that already exists, the
system updates the existing account's metadata and permissions instead of rejecting the request. This
leads to a Denial of Service (DoS) on administrative functions and Privilege De-escalation of the root
account. This vulnerability is fixed in 2.0.0-beta.2. (CVE-2026-42609)

Solution

Update the getgrav/grav library and its related packages to version 2.0.0-beta.2 or later.

See Also

https://github.com/advisories/GHSA-rr73-568v-28f8

Plugin Details

Severity: High

ID: 441199

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 5/6/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.64

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:C/A:C

CVSS Score Source: CVE-2026-42609

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.3

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/5/2026

Vulnerability Publication Date: 5/5/2026

Reference Information

CVE: CVE-2026-42609