API Key Mismanagement in Grav Plugin by GetGrav
CVE-2026-80203

9.3CRITICAL

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-80203?

The Grav API plugin prior to version 1.0.18 contains a significant vulnerability due to improper enforcement of API key permissions. Specifically, the requireNotSuperTarget() function in UsersController.php checks the acting account's super admin status instead of validating the actual permission level of the API key in use. This oversight allows users with limited API key scopes, yet possessing super-admin accounts, to bypass restrictions. Consequently, they may perform critical actions such as disabling two-factor authentication for other super-admin users, deleting avatars, minting new API keys, or removing existing keys, posing severe risks to user account security.

Affected Version(s)

grav 0 < 1.0.18

grav 1.0.18

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

alham-rizvi
.