Privilege Escalation in Grav API Plugin by Get Grav
CVE-2026-72833

8.7HIGH

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
14 August 2026

What is CVE-2026-72833?

The Grav API plugin for Get Grav versions between 1.0.6 and 1.0.11 contains a privilege escalation vulnerability that allows a scoped API key associated with a super-admin account to bypass its intended access restrictions. This incident occurs at four write endpoints (GroupsController, AccountsConfigController, PreferencesController, and DashboardWidgetController) where the system authorizes via an early-return method specific to super-admin access. This flaw results in the ability for a 'read-only' API key, such as one meant for monitoring or CI purposes, to execute operations reserved for super-admins, including the capability to modify group access control lists to elevate privileges for unauthorized accounts. The issue was addressed in version 1.0.13.

Affected Version(s)

grav 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.