RESTful API Vulnerability in Grav CMS API Plugin by Grav
CVE-2026-64852
8.7HIGH
What is CVE-2026-64852?
The Grav API Plugin, a RESTful interface for Grav CMS, had a significant vulnerability that allowed unauthorized users to generate and revoke API keys with admin permissions. Prior to version 1.0.8, the plugin did not properly validate the caller's authorization for sensitive actions, enabling a basic panel user to impersonate other accounts. This flaw could potentially grant admin-level access to restricted functionalities, exposing the site to severe security risks. The vulnerability has been addressed in version 1.0.8, emphasizing the need for users to update their installations promptly.
Affected Version(s)
grav-plugin-api < 1.0.8
