CVE-2026-72702: Origin Validation Error in getgrav grav
Description
Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, which validate the Referer header using an unanchored string prefix match (str_starts_with($referrer, $base)) with no trailing delimiter. An attacker who controls a domain that begins with the victim site's origin (e.g. https://example.com.attacker.tld) can send a request with such a Referer to be treated as same-origin, bypassing the Referer-based origin check.
CVSS v4.0
Score 9.3critical
Affected software
getgrav
grav
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Grav CMS (CVE-2026-72702) is caused by improper origin validation in the methods Grav\Common\Uri::referrer() and Grav\Common\Page\Pages::referrerRoute(). Both methods check if the HTTP Referer header starts with the site's root URL using str_starts_with($referrer, $base) where $base lacks a trailing slash or boundary character. This allows any Referer header beginning with the base string, including attacker-controlled domains like https://example.com.attacker.tld, to pass the check. The issue is a string prefix matching flaw without enforcing a delimiter boundary after the base URL. This vulnerability was confirmed in Grav CMS versions before 2.0.16, including commit c2b46866857a93a0aa7048e7ed707ed3ed45dbc3. The problem is similar to a previously fixed bug in version 2.0.15 but affects different code paths not covered by that fix. The flaw can be exploited without unusual browser configuration due to default Referrer Policy behavior. A proof-of-concept was demonstrated using the actual Grav source code.
Potential Impact
An attacker can bypass origin validation by sending a Referer header from a malicious domain that starts with the victim's origin string, potentially causing the application to trust a malicious referrer. This can lead to incorrect trust decisions based on the Referer header, which may affect application logic relying on origin checks. The vulnerability has a CVSS 4.0 score of 9.3 (critical), indicating high impact with no required privileges or user interaction. However, the exact impact depends on how the application uses the Referer header after validation.
Mitigation Recommendations
A fix is available in Grav CMS version 2.0.16 and later. Users should upgrade to version 2.0.16 or newer to address this vulnerability. The patch corrects the origin validation logic by enforcing a boundary character after the base URL when checking the Referer header. Until upgrading, users should be aware that the existing origin validation is insufficient and avoid relying on the Referer header for security decisions. No vendor advisory content was provided explicitly, so check the official Grav CMS release notes or security advisories for confirmation and further guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-10T13:02:20.829Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8cf57bacd9273b498428a8
Added to database: 08/25/2026, 01:52:59 UTC
Last enriched: 09/18/2026, 01:28:25 UTC
Last updated: 10/08/2026, 18:48:48 UTC
Views: 190
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.