Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100669— Grav before 2.0.25 Sensitive File Disclosure via Case-Variation Bypass

Quick assessment

Affected
getgrav grav
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述信息的中文翻译: 在 Grav 2.0.25 之前的版本中,随附的 Web 服务器配置示例文件中的访问控制拒绝规则存在区分大小写的匹配问题。在 (IIS)文件中,所有拒绝规则(包括 、 、 、 、 、 、 、 )均在其 URL 重写 元素中设置了 ,这覆盖了 IIS 默认设置的 。由于这些规则属于 URL 重写匹配(而非 元素),因此不存在不区分大小写的降级机制。 在运行于区分大小写文件系统(注:此处原文有误,NTFS 默认不区分大小写,但 IIS 本身默认配置是不区分大小写的;结合上下文,漏洞利用

CVSS 7.5 · High EPSS 0.44% · P36
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100669

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Grav before 2.0.25 Sensitive File Disclosure via Case-Variation Bypass
Source: CVE Program / CVE List V5
Vulnerability Description
Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In webserver-configs/web.config (IIS), every deny rule (user_sensitive_folders, user_accounts, user_data, user_error_redirect, user_pages, system, vendor, ignore_folders) sets ignoreCase="false" on its URL Rewrite <match> element, overriding the IIS default of ignoreCase="true"; because these are rewrite matches rather than <requestFiltering> elements, there is no case-insensitive fallback. On IIS running over case-insensitive NTFS, an unauthenticated remote attacker can vary the case of a folder name or file extension (for example GET /user/CONFIG/system.YAML) so that no deny rule matches and the IIS static file handler resolves and returns the underlying file, disclosing sensitive data such as configuration secrets or account password hashes. Whether a bypassed file is actually returned depends on MIME registration: .json is served by default, while .yaml/.yml return HTTP 404.3 on a stock IIS unless a YAML MIME mapping has been added. The same class of gap exists in the bundled webserver-configs/lighttpd.conf, whose user/(config|env), directory, script-extension, root-file and dotfile rules lack the (?i) modifier, though it is lower risk because lighttpd typically runs on case-sensitive filesystems. Deployments served by Apache (.htaccess), nginx, Caddy, or the PHP built-in server are not affected. The issue is fixed in 2.0.25; because the .htaccess installer heal does not touch web.config or lighttpd.conf, operators must re-copy the corrected sample files after upgrading.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
大小写敏感处理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
getgrav grav 0 ~ 2.0.25 -

II. Public POCs for CVE-2026-100669

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100669

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100669 (1)

Other References for CVE-2026-100669 (1)

Same Patch Batch · getgrav · 2026-09-26 · 7 CVEs total

CVE-2026-100670 8.8 HIGH Grav CMS 2.0.14 through 2.0.24 Privilege Escalation via Blueprint Guard Bypass
CVE-2026-100673 8.2 HIGH Grav Data Manager before 1.4.5 Stored XSS via item-detail view
CVE-2026-100671 8.0 HIGH Grav before 2.0.25 Session Cookie Theft via Twig Sandbox
CVE-2026-100672 7.5 HIGH grav-plugin-comments before 1.2.11 Unauthenticated Information Disclosure
CVE-2026-100668 6.5 MEDIUM Grav before 2.0.25 Sandbox Escape via array Filter
CVE-2026-100667 5.3 MEDIUM grav-plugin-login 3.8.7 through 3.9.6 Two-Factor Authentication Bypass

IV. Related Vulnerabilities

V. Comments for CVE-2026-100669

No comments yet


Leave a comment