CVE-2026-62667 | getgrav grav-plugin-api up to 1.0.5 ApiKeyManager authenticate scopes privileges management
A vulnerability labeled as critical has been found in getgrav grav-plugin-api up to 1.0.5. This affects the function ApiKeyAuthenticator::authenticate of the component ApiKeyManager. The manipulation of the argument scopes results in improper privilege management.
This vulnerability is identified as CVE-2026-62667. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.VulDB Recent EntriesRead More