What is CVE-2026-72830?
Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with limited permissions can inject arbitrary commands via scheduler.custom_jobs that execute through Symfony Process. Upgrade the plugin immediately.
Azərbaycanca: Grav API plaginin 1.0.13-dən əvvəlki versiyalarında ConfigController super-scope qapılarında API açarı scope məhdudiyyətləri tətbiq edilmir, bu da məhdud icazəli açarlara scheduler konfiqurasiyasını yazmağa imkan verir. Təcavüzkar scheduler.custom_jobs vasitəsilə Symfony Process ilə işə düşən ixtiyari əmrlər yeridə bilər. Plagin ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Grav
FAQ2
Which versions of the Grav API plugin are affected by CVE-2026-72830?
Versions before 1.0.13 are affected.
How can an attacker exploiting CVE-2026-72830 inject arbitrary commands?
By leveraging the failure to enforce API key scope caps in ConfigController super-scope gates, attackers with scoped keys can write to scheduler configuration and inject arbitrary commands via scheduler.custom_jobs that execute through Symfony Process.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.