What is CVE-2026-65007?
CVE-2026-65007 is a vulnerability in the Grav api plugin (grav-plugin-api) before version 1.0.8 where API key generation and revocation actions lack proper authorization. It allows users with only the admin.login permission to bypass account-management ACL checks and perform unauthorized API key operations. Affected installations should update the plugin to version 1.0.8 or later.
Azərbaycanca: CVE-2026-65007 zəifliyi Grav api plugin-in 1.0.8-dən əvvəlki versiyalarında API açarı generasiyası və ləğvi əməliyyatlarında səlahiyyət yoxlamasının düzgün aparılmaması ilə bağlıdır. Bu, aşağı səviyyəli admin.login icazəsi olan istifadəçilərin hesab idarəetmə ACL yoxlamasından yan keçərək icazəsiz API açarı əməliyyatları həyata keçirməsinə imkan verir. Təsirə məruz qalan sistemlərdə plaqini ən azı 1.0.8 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Who can exploit the CVE-2026-65007 vulnerability?
Users with only the admin.login permission can exploit this vulnerability to bypass account-management ACL checks and perform unauthorized API key operations.
How can the CVE-2026-65007 vulnerability be fixed?
Affected installations should update the Grav api plugin to version 1.0.8 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.