CVE-2026-65895: Grav API Plugin before 1.0.10 Broken Access Control

Published Jul 23, 2026
·
Updated

Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable credential brute-forcing attacks and reconfigure CORS policies to include attacker-controlled origins with credentials enabled.

Affected Software

1 affected component
Grav API plugin<1.0.10

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Grav API Plugin to a version that resolves this vulnerability.

    Fixed in 1.0.10
  2. Configuration

    Ensure site-wide rate limiting is enabled; prevent authenticated users with api.config.write from disabling it (Grav API Plugin versions before 1.0.10 have broken access control for write to security-critical configuration scopes).

    Grav API Plugin rate limiting site-wide (enable/disable) = enable
  3. Configuration

    Reconfigure CORS to exclude attacker-controlled origins and ensure credentials are not enabled for untrusted origins (Grav API Plugin versions before 1.0.10 can be used to reconfigure CORS settings due to broken access control).

    Grav API Plugin CORS policy (origins and credentials) = Restrict origins to trusted origins and disable credentials for attacker-controlled origins

Event History

Jul 23, 2026
CVE Published
via MITRE·11:42 AM
Data Sourced
via MITRE·11:42 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-65895?

CVE-2026-65895 has a severity rating of 8.5, classified as high.

2

How do I fix CVE-2026-65895?

To mitigate CVE-2026-65895, upgrade to Grav API Plugin version 1.0.10 or later.

3

What is the risk associated with CVE-2026-65895?

CVE-2026-65895 carries a risk score of 55, indicating significant potential impact.

4

What type of vulnerability is CVE-2026-65895?

CVE-2026-65895 is a broken access control vulnerability that allows unauthorized modification of crucial configuration settings.

5

Who is affected by CVE-2026-65895?

Authenticated users with the api.config.write privilege on Grav API Plugin versions before 1.0.10 are affected by CVE-2026-65895.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203