Authentication Bypass in Grav CMS Scheduler Webhook Plugin
CVE-2026-57852

6.3MEDIUM

Key Information:

Vendor
CVE Published:
20 July 2026

What is CVE-2026-57852?

The Grav CMS Scheduler Webhook Plugin is affected by an authentication bypass vulnerability, enabling unauthenticated remote attackers to exploit a flaw in the webhook token validation mechanism. By leveraging this flaw, attackers can send a single unauthenticated POST request to the scheduler webhook endpoint, which allows them to execute any scheduled jobs that have been configured. This risk can lead to the unintended execution of commands defined by operators, potentially compromising the security of the web server and the integrity of the applications running on it.

Affected Version(s)

Grav CMS scheduler-webhook plugin 0 <= 1.1.3

Grav CMS scheduler-webhook plugin 0 <= 1.1.3

Grav CMS scheduler-webhook plugin 0 <= 2.0.8

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Saidakbarxon Maxsudxonov
.