API Key Scope Bypass in Grav Plugin by Getgrav
CVE-2026-80204
9.3CRITICAL
What is CVE-2026-80204?
The Grav API plugin prior to version 1.0.18 has a flaw in the injectSecurityTab() function of the BlueprintController, which fails to properly limit the scope of API keys. This oversight allows users with a scoped API key to access and potentially modify page permission settings beyond their authorized scope. The lack of adequate security checks means that permissions can be incorrectly applied, posing a significant risk of unauthorized access and configuration changes.
Affected Version(s)
grav 0 < 1.0.18
grav 1.0.18
