What is CVE-2026-63407?
This vulnerability exists in Grav API Plugin versions prior to 1.0.0-rc.16. The CorsMiddleware incorrectly returns Access-Control-Allow-Origin: * and permissive OPTIONS responses for authenticated /api/v1 endpoints. This allows JavaScript from any origin to make authenticated API requests, so updating to the latest version is strongly recommended.
Azərbaycanca: Bu boşluq Grav API Plugin-in köhnə versiyalarında (1.0.0-rc.16-dan əvvəl) mövcuddur. Autentifikasiya tələb edən /api/v1 endpoint-ləri üçün CorsMiddleware səhv konfiqurasiya edilmiş Access-Control-Allow-Origin: * başlığı göndərir. Bu, istənilən mənşədən olan JavaScript-in autentifikasiya olunmuş API sorğuları göndərməsinə imkan verir, ona görə də plugin-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of Grav API Plugin are affected by CVE-2026-63407?
This vulnerability exists in Grav API Plugin versions prior to 1.0.0-rc.16.
What can an attacker do by exploiting this vulnerability?
Because CorsMiddleware is misconfigured, JavaScript from any origin can make authenticated API requests.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.