CVE-2026-72828 | getgrav Grav up to 1.0.12 InvitationsController isSuperAdmin permission

SecurityVulns

A vulnerability, which was classified as critical, has been found in getgrav Grav up to 1.0.12. Impacted is the function isSuperAdmin of the component InvitationsController. The manipulation leads to permission issues.

This vulnerability is traded as CVE-2026-72828. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More