CVE-2026-72696: Improper Link Resolution Before File Access ('Link Following') in getgrav grav
Grav CMS versions before 2.0.16 have a symlink following vulnerability in the Scheduler Job::createLockFile() function. This flaw allows local attackers to overwrite arbitrary files by creating symbolic links at predictable lock file paths in the world-writable temporary directory. When the scheduled job runs, it follows the symlink and overwrites the target file with the job ID string.
AI Analysis
Technical Summary
CVE-2026-72696 is a symlink following vulnerability in Grav CMS prior to version 2.0.16. The issue exists in the Scheduler Job::createLockFile() method, which creates lock files in a world-writable temporary directory. An attacker with local access can pre-create a symbolic link at the expected lock file path pointing to any file writable by the web server process. When the scheduled job executes, it follows the symlink and overwrites the target file's content with the job ID string, leading to arbitrary file overwrite.
Potential Impact
This vulnerability allows local attackers to overwrite arbitrary files that the web server process can write to, potentially leading to data corruption, privilege escalation, or denial of service depending on the overwritten file. The CVSS 4.0 score is 8.6 (high severity), reflecting the significant impact of arbitrary file overwrite without requiring user interaction or privileges beyond local access.
Mitigation Recommendations
No official patch or remediation is currently confirmed. Users should check the vendor advisory for updates. Until a fix is available, restrict local access to trusted users only and limit write permissions on the temporary directory to prevent symlink creation at predictable lock file paths.
CVE-2026-72696: Improper Link Resolution Before File Access ('Link Following') in getgrav grav
Description
Grav CMS versions before 2.0.16 have a symlink following vulnerability in the Scheduler Job::createLockFile() function. This flaw allows local attackers to overwrite arbitrary files by creating symbolic links at predictable lock file paths in the world-writable temporary directory. When the scheduled job runs, it follows the symlink and overwrites the target file with the job ID string.
CVSS v4.0
Score 8.6high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-72696 is a symlink following vulnerability in Grav CMS prior to version 2.0.16. The issue exists in the Scheduler Job::createLockFile() method, which creates lock files in a world-writable temporary directory. An attacker with local access can pre-create a symbolic link at the expected lock file path pointing to any file writable by the web server process. When the scheduled job executes, it follows the symlink and overwrites the target file's content with the job ID string, leading to arbitrary file overwrite.
Potential Impact
This vulnerability allows local attackers to overwrite arbitrary files that the web server process can write to, potentially leading to data corruption, privilege escalation, or denial of service depending on the overwritten file. The CVSS 4.0 score is 8.6 (high severity), reflecting the significant impact of arbitrary file overwrite without requiring user interaction or privileges beyond local access.
Mitigation Recommendations
No official patch or remediation is currently confirmed. Users should check the vendor advisory for updates. Until a fix is available, restrict local access to trusted users only and limit write permissions on the temporary directory to prevent symlink creation at predictable lock file paths.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-10T13:02:20.828Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a8cf57aacd9273b49842879
Added to database: 08/25/2026, 01:52:58 UTC
Last enriched: 08/25/2026, 02:08:55 UTC
Last updated: 08/25/2026, 02:12:20 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.