Broken Access Control in Grav API Plugin Affects Grav CMS
CVE-2026-65895
8.2HIGH
What is CVE-2026-65895?
The Grav API Plugin, prior to version 1.0.10, is susceptible to a broken access control vulnerability. This flaw permits authenticated users with 'api.config.write' privileges to alter critically sensitive configurations, including rate limiting and CORS settings. By disabling site-wide rate limiting, attackers can facilitate credential brute-forcing attacks. Additionally, they can reconfigure CORS policies to permit malicious origins, posing a significant threat to the security integrity of affected systems.
Affected Version(s)
grav 0 < 1.0.10
grav 1.0.10
