Authentication Bypass in Grav API Plugin by GetGrav
CVE-2026-62386

8.2HIGH

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
17 July 2026

What is CVE-2026-62386?

The Grav API plugin allows the extraction of JWT access tokens through the URL query parameter. This implementation exposes sensitive tokens in various logs, including web server access logs and browser history, leading to unauthorized access to the API. An attacker with access to these tokens can manipulate user data, configure system settings, and manage admin accounts, highlighting serious implications for platform security.

Affected Version(s)

grav 0 < 1.0.0-rc.16

grav 1.0.0-rc.16

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nicl4ssic
.