CVE-2026-72822 | Getgrav Grav up to 1.0.12 grav-plugin-api disable requirePermission privileges management
A vulnerability identified as critical has been detected in Getgrav Grav up to 1.0.12. Affected is the function requirePermission of the file /api/v1/users/{user}/2fa/disable of the component grav-plugin-api. The manipulation leads to improper privilege management.
This vulnerability is listed as CVE-2026-72822. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More