CVE-2026-64852 | Getgrav API Plugin up to 1.0.7 ApiKeyManager user/plugins/api/api.php privileges management
A vulnerability, which was classified as critical, has been found in Getgrav API Plugin up to 1.0.7. The impacted element is an unknown function of the file user/plugins/api/api.php of the component ApiKeyManager. The manipulation leads to improper privilege management.
This vulnerability is documented as CVE-2026-64852. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More