Authentication Bypass in Grav CMS Scheduler Webhook Plugin
CVE-2026-57852
6.3MEDIUM
What is CVE-2026-57852?
The Grav CMS Scheduler Webhook Plugin is affected by an authentication bypass vulnerability, enabling unauthenticated remote attackers to exploit a flaw in the webhook token validation mechanism. By leveraging this flaw, attackers can send a single unauthenticated POST request to the scheduler webhook endpoint, which allows them to execute any scheduled jobs that have been configured. This risk can lead to the unintended execution of commands defined by operators, potentially compromising the security of the web server and the integrity of the applications running on it.
Affected Version(s)
Grav CMS scheduler-webhook plugin 0 <= 1.1.3
Grav CMS scheduler-webhook plugin 0 <= 1.1.3
Grav CMS scheduler-webhook plugin 0 <= 2.0.8
