CVE-2026-63408 | GetGrav Grav API Plugin prior 1.0.0-rc.16 JwtAuthenticator extractBearerToken token information disclosure

SecurityVulns

A vulnerability was found in GetGrav Grav API Plugin. It has been declared as problematic. Affected by this issue is the function JwtAuthenticator::extractBearerToken of the component JwtAuthenticator. Executing a manipulation of the argument token can lead to information disclosure.

This vulnerability is handled as CVE-2026-63408. The attack can be executed remotely. There is not any exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More