What is CVE-2026-64852?
CVE-2026-64852 is a privilege escalation vulnerability found in the Grav API plugin for Grav CMS. Prior to version 1.0.8, a basic panel user with only 'admin.login' permission could perform critical actions like generating or revoking API keys without proper authorization. Users must upgrade the Grav API Plugin to at least version 1.0.8 to mitigate the issue.
Azərbaycanca: CVE-2026-64852 Grav CMS-in API plaginində aşkar edilmiş səlahiyyət yüksəltmə zəifliyidir. 1.0.8 versiyasından əvvəl, 'admin.login' icazəsi olan sadə panel istifadəçisi API açarı yaratmaq və ya ləğv etmək kimi kritik əməliyyatları icra edə bilər. Təhlükəsizlik üçün Grav API Plugin-i ən azı 1.0.8 versiyasına yeniləmək lazımdır.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which plugin is affected by CVE-2026-64852?
This vulnerability affects the API plugin for Grav CMS.
To mitigate CVE-2026-64852, to which version should the Grav API Plugin be upgraded?
The Grav API Plugin must be upgraded to at least version 1.0.8.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.