Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-65008 -- CVSS 9.8 Vulnerability Briefing

CVE-2026-65008 | CVSS 9.8 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-65008 is a critical remote code execution vulnerability in Grav 2.0.4, affecting the Blueprint::dynamicData() function in system/src/Grav/Common/Data/Blueprint.php.

Technical Detail

The vulnerable function passes a Class::method callable string and associated input for invocation, creating a path that can permit unintended method execution. An attacker who can cause crafted data to be processed by Blueprint::dynamicData() may be able to execute code on the Grav server. Successful exploitation could result in remote code execution with the privileges of the Grav web application process.

Exploitation Status

No known exploit has been reported as of July 28, 2026. This CVE is not listed in CISA's Known Exploited Vulnerabilities catalog.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Upgrade Grav installations from version 2.0.4 to version 2.0.7 or a later supported release, which contains the fix. Prioritize internet-accessible Grav instances and systems where untrusted users can submit or modify Blueprint-related data. If an immediate upgrade is not possible, restrict access to interfaces that process Blueprint data and prevent untrusted users from modifying Blueprint definitions; these are compensating controls, not a confirmed remediation. Monitor web and application logs for unexpected requests involving Blueprint processing, application errors, and anomalous child-process or command execution by the web server account.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →