API Key Scope Bypass in Grav Plugin by GetGrav
CVE-2026-72826
9.3CRITICAL
What is CVE-2026-72826?
The Grav Plugin API prior to version 1.0.13 is susceptible to a scope bypass vulnerability. This issue arises when an API key is created without proper validation of its scopes, allowing attackers to leverage a minimal-scope key from a super account to generate a full-access super key through an empty scopes array. This circumvention can lead to severe security breaches, including unauthorized access to configurations and potential remote code execution.
Affected Version(s)
grav 0 < 1.0.13
grav 1.0.13
