CVE-2026-72833: Grav 1.0.6 through 1.0.11 Privilege Escalation via Scoped API Keys
The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulnerability. A scoped API key minted on a super-admin account bypasses its declared scope cap on four isSuperAdmin()-gated write endpoints (in GroupsController, AccountsConfigController, PreferencesController, and DashboardWidgetController). These endpoints authorize via a super-admin early-return that never invokes requirePermission()—the sole enforcement point of the scope cap—so a 'read-only'-scoped key (e.g. api.pages.read) can perform super-only write operations, including rewriting group ACL maps to grant super-admin privileges to arbitrary accounts. A leaked or delegated read-only CI/monitoring key can therefore gain full super-admin write capability. Fixed in 1.0.13.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
getgrav/grav-plugin-apito a version that resolves this vulnerability.Fixed in 1.0.13 - Compensating control
Revoke/rotate any potentially leaked or delegated CI/monitoring key and any scoped API keys minted from a super-admin account (read-only scope such as api.pages.read) that could have been used to call the isSuperAdmin()-gated write endpoints (GroupsController, AccountsConfigController, PreferencesController, DashboardWidgetController).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72833?
The severity of CVE-2026-72833 is high, with a score of 8.8 according to the CVSS metrics.
How do I fix CVE-2026-72833?
To fix CVE-2026-72833, upgrade the Grav API plugin to version 1.0.12 or later.
What versions of the Grav API plugin are affected by CVE-2026-72833?
Grav API plugin versions between 1.0.6 and 1.0.11 are affected by CVE-2026-72833.
What type of vulnerability is CVE-2026-72833?
CVE-2026-72833 is classified as a privilege escalation vulnerability.
What consequences can arise from CVE-2026-72833?
Exploitation of CVE-2026-72833 can allow unauthorized users to gain super-admin rights through scoped API keys.