Privilege Escalation in Grav API Plugin Affecting Grav
CVE-2026-65897
8.7HIGH
What is CVE-2026-65897?
The Grav API Plugin versions prior to 1.0.10 have a critical flaw in the InvitationsController::create() method that lacks proper validation for the groups field. This vulnerability allows authenticated users with api.users.write permissions to invite accounts to groups with elevated privileges. Consequently, attackers can create invitation records granting super-admin API access to new accounts, bypassing the inviter's permission levels, which poses a significant security risk.
Affected Version(s)
grav 0 < 1.0.10
grav 1.0.10
