CVE-2026-57852: Authentication Bypass via Null Short-Circuit in Grav CMS Scheduler Webhook Token Check
Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured scheduled jobs by exploiting a short-circuit logic flaw in the webhook token validation. Attackers can send a single unauthenticated POST request to the scheduler webhook endpoint to execute all configured scheduled jobs or target a specific job, causing unintended execution of operator-defined commands under the web server process user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57852?
The severity of CVE-2026-57852 is rated as medium with a score of 5.6.
How do I fix CVE-2026-57852?
To fix CVE-2026-57852, update to the latest version of the Grav CMS scheduler-webhook plugin that contains the required security patches.
What type of vulnerability is CVE-2026-57852?
CVE-2026-57852 is an authentication bypass vulnerability affecting the Grav CMS scheduler-webhook plugin.
Can CVE-2026-57852 be exploited remotely?
Yes, CVE-2026-57852 can be exploited remotely by unauthenticated attackers.
What impact does CVE-2026-57852 have on affected systems?
CVE-2026-57852 allows attackers to trigger configured scheduled jobs, potentially leading to unauthorized actions on affected Grav CMS systems.