{"id":"CVE-2026-55885","aliases":["GHSA-2f86-9cp8-6hcf"],"url":"https://o3.security/vulnerability/CVE-2026-55885","summary":"Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets","details":"Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the full Grav installation root, including user/accounts/admin.yaml with the administrator password hash and user/config with site configuration, through the backup download endpoint protected only by the session-static admin-nonce URL parameter. This issue is reported as fixed in version 1.7.53.","published":"2026-07-10T16:13:48.649Z","modified":"2026-08-12T03:51:12.832634328Z","cvss":{"score":6.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"},"epss":{"score":0.00265,"percentile":0.18209,"asOf":"2026-09-07"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"getgrav/grav","fixedVersion":"1.7.53"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/getgrav/grav/releases/tag/1.7.53"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55885.json"},{"type":"ADVISORY","url":"https://github.com/getgrav/grav/security/advisories/GHSA-2f86-9cp8-6hcf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55885"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:12.832634328Z"}}