What is CVE-2026-75832?
CVE-2026-75832 is a missing authorization vulnerability in the Grav API plugin (before 1.0.14) within the `BlueprintPathResolver::resolveUserScope()` method. This flaw may improperly gate `users/<name>` scope on the account's raw super-admin ACL flag, potentially allowing unauthorized access. Users must update to version 1.0.15 immediately.
Azərbaycanca: CVE-2026-75832, Grav CMS-in API plaginində (1.0.14-dən əvvəlki versiyalar) `BlueprintPathResolver::resolveUserScope()` metodunda avtorizasiya çatışmazlığıdır. Bu zəiflik super-admin imtiyazlarını yoxlamadan `users/<name>` sorğularına icazə verə bilər. Grav API plagini istifadəçiləri dərhal 1.0.15 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: getgrav
FAQ2
In which component was CVE-2026-75832 discovered and what is its primary impact?
CVE-2026-75832 was discovered in the Grav API plugin before version 1.0.14, specifically within the `BlueprintPathResolver::resolveUserScope()` method. It is a missing authorization flaw that may improperly gate the `users/<name>` scope on the account's raw super-admin ACL flag.
What is the recommended mitigation for CVE-2026-75832?
Users of the Grav API plugin must update to version 1.0.15 immediately to address this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.