PT-2026-63977 · Grav · Grav-Plugin-Api

·

CVE-2026-65897

·

Published

2026-07-23

·

Updated

2026-07-23

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grav API Plugin versions prior to 1.0.10
Description Insufficient validation of the groups field within the InvitationsController::create() function allows authenticated users with api.users.write permissions to assign invited accounts to groups that grant api.super permissions. This enables an attacker to create invitation records with elevated group membership, granting the new account full super-admin API access regardless of the inviter's own permission level.
Recommendations Update Grav API Plugin to version 1.0.10 or later.

Exploit

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65897
GHSA-M86M-JJCG-GCVV

Affected Products

Grav-Plugin-Api