What is CVE-2026-72833?
CVE-2026-72833 is a privilege escalation vulnerability in the Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11. A scoped API key from a super-admin account bypasses its declared scope on four `isSuperAdmin()`-gated write endpoints, including GroupsController and AccountsConfigController. Update the plugin to the latest version.
Azərbaycanca: CVE-2026-72833, Grav API plagininin 1.0.6-1.0.11 versiyalarında aşkar edilmiş imtiyaz artırma (privilege escalation) boşluğudur. Super-admin hesabı ilə yaradılmış məhdud API açarı, `isSuperAdmin()` ilə qorunan dörd yazma endpointində (GroupsController, AccountsConfigController) əhatə dairəsini keçə bilər. Plagin ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-269; shared vendor: getgrav
FAQ2
Which versions of the Grav API plugin are affected by CVE-2026-72833?
Versions from 1.0.6 to 1.0.11, meaning the range >= 1.0.6 and <= 1.0.11, are affected.
What does CVE-2026-72833 allow?
A scoped API key from a super-admin account bypasses its declared scope on four `isSuperAdmin()`-gated write endpoints, leading to privilege escalation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.