Authentication Bypass in Grav API Plugin by GetGrav
CVE-2026-62386
8.2HIGH
What is CVE-2026-62386?
The Grav API plugin allows the extraction of JWT access tokens through the URL query parameter. This implementation exposes sensitive tokens in various logs, including web server access logs and browser history, leading to unauthorized access to the API. An attacker with access to these tokens can manipulate user data, configure system settings, and manage admin accounts, highlighting serious implications for platform security.
Affected Version(s)
grav 0 < 1.0.0-rc.16
grav 1.0.0-rc.16
