PT-2026-78519 · Grav · Api Plugin

CVE-2026-64852

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grav API Plugin versions prior to 1.0.8
Description The plugin intercepts the apiKeyGenerate and apiKeyRevoke admin tasks in the user/plugins/api/api.php file but only authorizes the caller with admin.login. This allows a basic panel user to select another account via the route and create a persistent ApiKeyManager credential bound to that target. Consequently, the user can inherit the target account's API permissions, which may include api.super or administrative write access.
Recommendations Update Grav API Plugin to version 1.0.8.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64852
GHSA-7V74-M76Q-8WF3

Affected Products

Api Plugin