INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ShinyHunters Exploited Grav CMS Path Traversal Flaw to Hacked Clop
| 2026-09-25 20:57 CRITICAL LOW DATA BREACH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The Clop ransomware gang's data leak site was breached by the ShinyHunters extortion gang on an unpatched Grav CMS flaw, specifically a path traversal vulnerability in form upload handling. The attack occurred earlier this month and involved exploiting values supplied through POST parameters when creating temporary directories without validation. As a result of the breach, Clop's server contained only content with no valuable operational or financial data, according to the Russian ransomware gang. ShinyHunters claimed they stole source code, Grav CMS plugins, server logs, and private keys used by Clop's Tor onion service from the compromised server. The attack has been resolved as the Clop leak site was moved to a new Tor address after being defaced with a full-page display of its Umbreon Pokémon logo.
Technical Mitigations AI-generated
• SanitizeId() function in Grav CMS 2.0 (2.0.0-beta.2) to prevent path traversal attacks
• Update to Grav CMS version 1.7.43 or later, as the vulnerability is tracked as CVE-2026-42608 and has been fixed in newer versions
• Validate form-related POST parameters before creating temporary upload directories
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
UmbreonUmbreon
CVE-2026-42608CVE-2026-42608
Target & Sectors
RU
Incident Timeline
April 27
Threat actors exploited a privately reported path traversal vulnerability in Grav CMS, tracked as CVE-2026-42608, which was fixed in version 2.0.0-beta.2 earlier this year.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-42608
Grav said the flaw is tracked as
CVE-2026-42608
and is a path traversal vulnerability that was privately reported and
fixed in Grav 2.0 (2.0.0-beta.2)
earlier this year, with
the advisory
published on April 27.
infrastructure
2.0
Grav said the flaw is tracked as
CVE-2026-42608
and is a path traversal vulnerability that was privately reported and
fixed in Grav 2.0 (2.0.0-beta.2)
earlier this year, with
the advisory
published on April 27.
infrastructure
2.0.0-beta
Grav said the flaw is tracked as
CVE-2026-42608
and is a path traversal vulnerability that was privately reported and
fixed in Grav 2.0 (2.0.0-beta.2)
earlier this year, with
the advisory
published on April 27.
general_metric
2.0 Grav
Grav said the flaw is tracked as
CVE-2026-42608
and is a path traversal vulnerability that was privately reported and
fixed in Grav 2.0 (2.0.0-beta.2)
earlier this year, with
the advisory
published on April 27.
2026/09/24
Threat actors exploited a Grav CMS path traversal flaw to target the Clop leak site, which was later patched by releasing version 1.7.53.4 of the software on September 24, 2026.
Click on any entity below to view its context and source!
infrastructure
1.7
After BleepingComputer shared the exploitation details with Grav, the developers backported the fix to the 1.7 branch and
released Grav 1.7.53.4 yesterday
.
general_metric
1.7 older branch
After BleepingComputer shared the exploitation details with Grav, the developers backported the fix to the 1.7 branch and
released Grav 1.7.53.4 yesterday
.
infrastructure
1.7.53
After BleepingComputer shared the exploitation details with Grav, the developers backported the fix to the 1.7 branch and
released Grav 1.7.53.4 yesterday
.
2026/09/25
ShinyHunters exploited an unauthenticated path traversal vulnerability in Grav CMS version 1.7.43 to breach the Clop leak site, which was later defaced with a full-page defacement displaying its Umbreon Pokémon logo and a link to its own data leak site.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
However, the Russian ransomware gang disputes ShinyHunters' claims that valuable operational or financial data was stolen from the compromised server.
The
Clop leak site was breached earlier this month
by the ShinyHunters extortion gang, which first uploaded a small text file and later replaced the site with a full-page defacement displaying its Umbreon Pokémon logo and a link to its own data leak site.
Clop data leak site defaced by ShinyHunters
ShinyHunters later claimed on its own data leak site that it stole source code, Grav CMS plugins, server logs, and the private keys used by Clop's Tor onion service.
While Clop says they are not communicating with the other threat actors, they have since been quietly removed from ShinyHunters' data leak site, which commonly happens when negotiations are taking place.
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw.
Clop also denied having any relationship or ongoing negotiations with ShinyHunters.
When asked whether the group had determined how ShinyHunters breached the leak site, Clop confirmed that its Grav installation had not been fully updated.
When questioned about the removal, ShinyHunters told BleepingComputer that they did not want to answer any further questions about this.
Grav confirms flaw used in attack
Grav CMS has now confirmed that the vulnerability and exploitation details shared by ShinyHunters with BleepingComputer are accurate.
ShinyHunters told BleepingComputer that the compromised Clop server was running Grav CMS 1.7.43 and claimed it exploited an unauthenticated file upload flaw in Grav's form upload handling.
The group specifically identified the
__unique_form_id__
parameter and said the value was added into a temporary path like:
tmp/forms/<session_id>/<unique_id>
ShinyHunters claimed that by supplying directory traversal sequences, such as
../../../shhq
, for the unique form identifier, it could cause Grav to create an upload path outside the intended
tmp/forms
directory.
[A-Za-z0-9,_-]{1,64}
Grav confirmed that this sanitization method is the same mitigation described by ShinyHunters to BleepingComputer.
organisation
Tor
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability.
organisation
BleepingComputer
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability.
infrastructure
2.0
"Grav 2.0 is the current major version, but plenty of sites are still on 1.7, and that fix hadn't been backported there yet."
infrastructure
1.7
"Grav 2.0 is the current major version, but plenty of sites are still on 1.7, and that fix hadn't been backported there yet."
However, while current Grav 2.x releases had already been protected, the fix had not been backported to the older Grav 1.7 branch, leaving installations such as Clop's 1.7.43 deployment vulnerable.
Grav is urging anyone still running the 1.7 branch to upgrade to version 1.7.53.4.
infrastructure
1.7.43
However, while current Grav 2.x releases had already been protected, the fix had not been backported to the older Grav 1.7 branch, leaving installations such as Clop's 1.7.43 deployment vulnerable.
infrastructure
1.7.53
Grav is urging anyone still running the 1.7 branch to upgrade to version 1.7.53.4.
infrastructure
7.3.0
"The bug lives in Grav core, not the Form plugin, so the Form plugin version (7.3.0 in their example) doesn't change whether a site is vulnerable.
organisation
POST
According to the threat actor, the vulnerable code used values supplied through form-related POST parameters when creating temporary upload directories without first validating them as safe filesystem path components.
organisation
CMS
After BleepingComputer shared the technical details with Grav, the CMS developers confirmed that the threat actor's description was accurate.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tactical Metrics
Metrics
infrastructure
2.0
Software Version
Click for context!
Grav said the flaw is tracked as
CVE-2026-42608
and is a path traversal vulnerability that was privately reported and
fixed in Grav 2.0 (2.0.0-beta.2)
earlier this year, with
the advisory
published on April 27.
"Grav 2.0 is the current major version, but plenty of sites are still on 1.7, and that fix hadn't been backported there yet."
Metrics
infrastructure
2.0.0-beta
Software Version
Grav said the flaw is tracked as
CVE-2026-42608
and is a path traversal vulnerability that was privately reported and
fixed in Grav 2.0 (2.0.0-beta.2)
earlier this year, with
the advisory
published on April 27.
Metrics
infrastructure
1.7
Software Version
However, while current Grav 2.x releases had already been protected, the fix had not been backported to the older Grav 1.7 branch, leaving installations such as Clop's 1.7.43 deployment vulnerable.
"Grav 2.0 is the current major version, but plenty of sites are still on 1.7, and that fix hadn't been backported there yet."
After BleepingComputer shared the exploitation details with Grav, the developers backported the fix to the 1.7 branch and
released Grav 1.7.53.4 yesterday
.
Grav is urging anyone still running the 1.7 branch to upgrade to version 1.7.53.4.
Metrics
infrastructure
1.7.43
Software Version
However, while current Grav 2.x releases had already been protected, the fix had not been backported to the older Grav 1.7 branch, leaving installations such as Clop's 1.7.43 deployment vulnerable.
Metrics
infrastructure
1.7.53
Software Version
After BleepingComputer shared the exploitation details with Grav, the developers backported the fix to the 1.7 branch and
released Grav 1.7.53.4 yesterday
.
Grav is urging anyone still running the 1.7 branch to upgrade to version 1.7.53.4.
Metrics
infrastructure
7.3.0
Software Version
"The bug lives in Grav core, not the Form plugin, so the Form plugin version (7.3.0 in their example) doesn't change whether a site is vulnerable.
Intelligence Sources
BleepingComputer
2026-09-25
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T10:47
Comprehensive Tactical Telemetry
Highly Correlated Entities
6x
organisation
Identified Entity
Tor
entity
6x
infrastructure
Software Version
2.0
version
4x
tactic
Cyber Operation Type
Ransomware
tactic
2x
timeline
Temporal Reference
April 27
date
Contextual Telemetry
Context Block
6 METRICS
target region
Target Country
Russian Federation
country
threat actor
APT Group
ShinyHunters
actor
malware
Malware Payload
Umbreon
tool
vulnerability
Exploited CVE
CVE-2026-42608
cve
general metric
Grav
2
grav
general metric
Older Branch
2
older branch
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.