Remote Code Execution in Grav API Plugin by Grav
CVE-2026-72830
9.3CRITICAL
What is CVE-2026-72830?
The Grav API plugin versions prior to 1.0.13 contain a significant security flaw in which the enforcement of API key scope limitations is not properly implemented in the ConfigController super-scope gates. This oversight allows attackers who possess a scoped api.config.write key to manipulate the scheduler's configuration settings. By exploiting this weakness, adversaries can inject arbitrary commands into the scheduler.custom_jobs, which are then executed via the Symfony Process, enabling remote code execution and potentially compromising the entire application.
Affected Version(s)
grav 0 < 1.0.13
grav 1.0.13
