What is CVE-2026-72822?
The getgrav/grav-plugin-api Composer package versions up to 1.0.12 fail to enforce API key scope caps on the `disable2fa` endpoint. Unlike the `generate2fa` endpoint, it authorizes the admin path solely via ACL reads without invoking proper scope checks. Affected users should immediately update to version 1.0.13.
Azərbaycanca: getgrav/grav-plugin-api Composer paketinin 1.0.12 və daha əvvəlki versiyalarında `disable2fa` endpointində API açarının əhatə dairəsi məhdudiyyətləri düzgün tətbiq olunmur. Bu, `generate2fa` endpointindən fərqli olaraq admin yolunda yalnız ACL oxunuşları ilə icazə yoxlaması aparır. Təsirə məruz qalan sistemlərdə istifadəçilər dərhal 1.0.13 versiyasına yeniləmə etməlidirlər.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: getgrav
FAQ2
Which endpoint and versions of the `getgrav/grav-plugin-api` plugin are affected by CVE-2026-72822?
The vulnerability affects the `disable2fa` endpoint in the `getgrav/grav-plugin-api` Composer package versions up to 1.0.12.
What action should be taken to mitigate CVE-2026-72822?
Affected users should immediately update the `getgrav/grav-plugin-api` package to version 1.0.13.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.