{"id":"CVE-2026-62673","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-62673","summary":"Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess.txt security rules omit the Apache [NC] flag and therefore compare sensitive directory…","details":"Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess.txt security rules omit the Apache [NC] flag and therefore compare sensitive directory and file-extension patterns case-sensitively. On a case-insensitive filesystem, an unauthenticated requester can use uppercase directory or extension variants to bypass the rules and retrieve files under user/accounts or user/config, including password hashes and security configuration. This issue is fixed in version 2.0.4.","published":"2026-08-19T16:18:20.353","modified":"2026-08-19T16:18:20.353","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/getgrav/grav/commit/8c9d1e7b6fd66ecea80a4bc3783fd41d36e22fb1","label":"getgrav/grav@8c9d1e7"},"references":[{"type":"WEB","url":"https://github.com/getgrav/grav/commit/8c9d1e7b6fd66ecea80a4bc3783fd41d36e22fb1"},{"type":"WEB","url":"https://github.com/getgrav/grav/releases/tag/2.0.4"},{"type":"WEB","url":"https://github.com/getgrav/grav/security/advisories/GHSA-vwg3-w8w3-pc79"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-19T16:18:20.353"}}