PT-2026-60641 · Grav · Grav-Plugin-Api
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Grav API plugin versions prior to 1.0.6
Description
An authorization bypass exists because the
ApiKeyAuthenticator class fails to read or enforce the restricted scopes array when API keys are created. Consequently, a key intended for limited access, such as read-only, can be used to perform any write, delete, or administrative operation that the owning user is authorized to execute, as the system returns the full account object of the user.Recommendations
Update Grav API plugin to version 1.0.6.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav-Plugin-Api