What is CVE-2026-63408?
CVE-2026-63408 is a critical vulnerability in the Grav API Plugin for Grav CMS. Prior to version 1.0.0-rc.16, the JWT authentication mechanism accepts tokens from the URL query parameter, exposing state-changing API endpoints to unauthorized access. Immediate update to the latest plugin version is recommended.
Azərbaycanca: CVE-2026-63408 Grav CMS üçün API Plugin-də aşkarlanmış kritik bir zəiflikdir. 1.0.0-rc.16 versiyasından əvvəl, autentifikasiya mexanizmi JWT token-i URL sorğu parametrindən qəbul edərək state-changing API sorğularını qorunmasız qoyur. Dərhal plugin-i son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of the Grav API Plugin are affected by CVE-2026-63408?
All versions prior to 1.0.0-rc.16 are affected.
What issue does CVE-2026-63408 introduce in the authentication mechanism?
Accepting the JWT token from the URL query parameter exposes state-changing API endpoints to unauthorized access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.