Privilege Escalation in Grav API Plugin by Get Grav
CVE-2026-72833
What is CVE-2026-72833?
The Grav API plugin for Get Grav versions between 1.0.6 and 1.0.11 contains a privilege escalation vulnerability that allows a scoped API key associated with a super-admin account to bypass its intended access restrictions. This incident occurs at four write endpoints (GroupsController, AccountsConfigController, PreferencesController, and DashboardWidgetController) where the system authorizes via an early-return method specific to super-admin access. This flaw results in the ability for a 'read-only' API key, such as one meant for monitoring or CI purposes, to execute operations reserved for super-admins, including the capability to modify group access control lists to elevate privileges for unauthorized accounts. The issue was addressed in version 1.0.13.
Affected Version(s)
grav 0
