What is CVE-2026-72826?
In getgrav/grav-plugin-api versions prior to 1.0.13, the `createApiKey` function fails to validate that new API key scopes are a subset of the caller's scopes. This vulnerability allows users with only `api.access` scope to escalate privileges by creating keys with higher permissions; affected instances must immediately update to version 1.0.13 or later.
Azərbaycanca: getgrav/grav-plugin-api plaginin 1.0.13-dən əvvəlki versiyalarında, `createApiKey` funksiyası yeni API açarı yaradılarkən çağıran istifadəçinin `scopes` icazələrinin alt çoxluğu olub-olmadığını yoxlamır. Bu zəiflik aşağı səviyyəli `api.access` icazəsinə malik istifadəçilərə daha yüksək icazəli API açarları yaratmağa imkan verir, təsirlənən sistemlərdə plagin dərhal 1.0.13 və ya daha yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-269; shared vendor: getgrav
FAQ2
What is the CVE-2026-72826 vulnerability in the getgrav/grav-plugin-api plugin?
It is a privilege escalation vulnerability in versions prior to 1.0.13, where the `createApiKey` function fails to validate that the requested scopes are a subset of the calling user's scopes. This allows users with only `api.access` scope to create API keys with higher permissions.
How to mitigate the CVE-2026-72826 vulnerability?
All affected instances must immediately update the getgrav/grav-plugin-api plugin to version 1.0.13 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.