---
id: CVE-2026-62230
title: >-
  Grav before 2.0.4 ships a default .htaccess (and reference
  webserver-configs/htaccess.txt) whose rules blocking access to sensitive file
  types (.yaml, .php, .json, etc.) lack the [NC] flag, making extension matching
  case-sensitive
summary: >-
  Grav before 2.0.4 ships a default .htaccess (and reference
  webserver-configs/htaccess.txt) whose rules blocking access to sensitive file
  types (.yaml, .php, .json, etc.) lack the [NC] flag, making extension matching
  case-sensitive. On ca…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-178
vendor: getgrav
product: grav
affected:
  - grav < 2.0.4
published: '2026-07-17'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:26.780'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-62230'
references:
  - url: 'https://github.com/getgrav/grav/security/advisories/GHSA-vwg3-w8w3-pc79'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/grav-file-access-bypass-via-case-variation
    label: disclosure@vulncheck.com
  - url: 'https://github.com/getgrav/grav/security/advisories/GHSA-vwg3-w8w3-pc79'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-07-17T14:08:46.289266Z'
epss: 0.00479
epssPercentile: 0.39336
ingestedAt: '2026-10-08T16:52:14.702Z'
---

## Overview

Grav before 2.0.4 ships a default .htaccess (and reference webserver-configs/htaccess.txt) whose rules blocking access to sensitive file types (.yaml, .php, .json, etc.) lack the [NC] flag, making extension matching case-sensitive. On case-insensitive filesystems (Windows/NTFS, macOS/HFS+, or Docker volume mounts), an unauthenticated attacker can request these files with uppercase or mixed-case extensions (e.g., .YAML, .PHP) to bypass the restrictions and read sensitive configuration files that may contain API keys and credentials.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
