PT-2026-58868 · Grav · Grav-Plugin-Api
CVE-2026-62666
·
Published
2026-07-14
·
Updated
2026-08-21
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Grav API Plugin versions prior to 1.0.6
Description
UsersController functions
createApiKey(), generate2fa(), and disable2fa() fail to perform the accessGrantsSuper() target check. An account with api.users.write permissions can use requireApiKeyPermission() to create an API key linked to an access.api.super target. Because key scopes are not enforced, the attacker can obtain full super-administrator privileges and establish persistent access. Additionally, this flaw allows the rotation or disabling of two-factor authentication for the target account.Recommendations
Update Grav API Plugin to version 1.0.6.
Exploit
Fix
IDOR
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Grav-Plugin-Api