PT-2026-63975 · Grav · Api Plugin

·

CVE-2026-65895

·

Published

2026-07-23

·

Updated

2026-07-23

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Grav API Plugin versions prior to 1.0.10
Description Authenticated users with api.config.write privilege can modify security-critical plugin configuration scopes. This allows attackers to disable site-wide rate limiting, facilitating credential brute-forcing attacks, and reconfigure Cross-Origin Resource Sharing (CORS) policies to include attacker-controlled origins with credentials enabled.
Recommendations Update Grav API Plugin to version 1.0.10 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65895
GHSA-4PQV-2QJ5-38FP

Affected Products

Api Plugin