What is CVE-2026-62666?
In Grav API Plugin versions prior to 1.0.6, missing super user checks in the UsersController allow low-privileged accounts to perform critical actions like creating API keys, generating, and disabling 2FA. Affected instances must urgently upgrade to version 1.0.6 or later.
Azərbaycanca: Grav CMS-in RESTful API plaginində (1.0.6-dan əvvəlki versiyalarda) super istifadəçi yoxlamasının olmaması səbəbindən, aşağı səlahiyyətli hesablar API açarı yaratmaq, 2FA yaratmaq və söndürmək kimi kritik əməliyyatları icra edə bilər. Təsirə məruz qalan sistemlərdə təcili olaraq 1.0.6 və ya daha yuxarı versiyaya yeniləmə aparılmalıdır.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of Grav API Plugin are vulnerable to CVE-2026-62666?
All versions prior to 1.0.6 are affected by this vulnerability.
What critical actions can a low-privileged account perform by exploiting this vulnerability?
It can perform actions such as creating API keys, generating, and disabling 2FA.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.