PT-2026-60641 · Grav · Grav-Plugin-Api

·

CVE-2026-62231

·

Published

2026-07-17

·

Updated

2026-07-21

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grav API plugin versions prior to 1.0.6
Description An authorization bypass exists because the ApiKeyAuthenticator class fails to read or enforce the restricted scopes array when API keys are created. Consequently, a key intended for limited access, such as read-only, can be used to perform any write, delete, or administrative operation that the owning user is authorized to execute, as the system returns the full account object of the user.
Recommendations Update Grav API plugin to version 1.0.6.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62231
GHSA-X7HM-JC32-V39J

Affected Products

Grav-Plugin-Api