CVE-2026-72826 | getgrav grav-plugin-api up to 1.0.12 API Key Creation requireApiKeyPermission scopes privileges management
A vulnerability classified as critical has been found in getgrav grav-plugin-api up to 1.0.12. This vulnerability affects the function requireApiKeyPermission of the component API Key Creation. Performing a manipulation of the argument scopes results in improper privilege management.
This vulnerability is reported as CVE-2026-72826. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More