CVE-2026-75835: Grav API Plugin before 1.0.14 Missing Authorization

Published Aug 18, 2026
·
Updated

Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in userPassesAuthorize() (AbstractApiController.php). The function fails to consult the calling request's API key scopes, relying instead on the account's raw super-admin flag and ACL grants. As a result, an authenticated attacker holding a scoped API key minted on a privileged account can bypass their declared scope restrictions to access authorize-gated UI metadata and item definitions (sidebar/menubar/widget items and users-list columns/row-actions/filter-tabs) that their key scope should deny, resulting in information disclosure.

Affected Software

1 affected component
getgrav/grav-plugin-api<1.0.14

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade getgrav/grav-plugin-api to a version that resolves this vulnerability.

    Fixed in 1.0.14

Event History

Aug 18, 2026
CVE Published
via MITRE·11:19 AM
Data Sourced
via MITRE·11:19 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:19 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are realistically exposed?

The exposed population is deployments that use the Grav API plugin before 1.0.14 and issue scoped API keys from accounts with super-admin status or relevant ACL grants. The issue is reachable remotely by an authenticated attacker and does not require user interaction.

2

What credentials are required to exploit this?

An attacker needs a valid scoped API key that was minted on a privileged account. The key's declared scopes must deny access to the targeted authorize-gated UI metadata or item definitions, while the underlying account's super-admin flag or ACL grants permit it.

3

What can an attacker access after bypassing scope restrictions?

The attacker can disclose authorize-gated UI metadata and item definitions, including sidebar, menubar, and widget items, as well as users-list columns, row actions, and filter tabs. The provided data describes information disclosure only; it does not indicate integrity or availability impact.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203