RESTful API Vulnerability in Grav CMS API Plugin by Grav
CVE-2026-64852

8.7HIGH

Key Information:

Vendor

Getgrav

Vendor
CVE Published:
19 August 2026

What is CVE-2026-64852?

The Grav API Plugin, a RESTful interface for Grav CMS, had a significant vulnerability that allowed unauthorized users to generate and revoke API keys with admin permissions. Prior to version 1.0.8, the plugin did not properly validate the caller's authorization for sensitive actions, enabling a basic panel user to impersonate other accounts. This flaw could potentially grant admin-level access to restricted functionalities, exposing the site to severe security risks. The vulnerability has been addressed in version 1.0.8, emphasizing the need for users to update their installations promptly.

Affected Version(s)

grav-plugin-api < 1.0.8

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.