What is CVE-2026-72828?
Grav Plugin API before version 1.0.13 fails to enforce API-key scopes in InvitationsController, relying on a bare `isSuperAdmin()` check instead of scope-aware permissions. This allows a least-privilege API key scoped to limited actions to perform unauthorized operations. Immediately update the plugin to version 1.0.13 or later.
Azərbaycanca: Grav Plugin API (1.0.13-dən əvvəlki versiyalar) InvitationsController-da API açarının əhatə dairəsini (scope) düzgün yoxlamır, `isSuperAdmin()` sadə çağırışı ilə super admin hüquqları verir. Bu, ən aşağı səlahiyyətli API açarına malik istifadəçiyə belə icazəsiz əməliyyatlar aparmağa imkan tanıyır. Plugin-i dərhal 1.0.13 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: getgrav
FAQ2
What unauthorized operations can be performed using the CVE-2026-72828 vulnerability?
This vulnerability allows a user with a least-privilege API key to perform unauthorized operations that require super admin rights.
To which version should Grav Plugin API be updated to fix CVE-2026-72828?
It is recommended to immediately update the plugin to version 1.0.13 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.