CVE-2026-62666 | getgrav API Plugin up to 1.0.5 UsersController createApiKey/generate2fa/disable2fa privileges management
A vulnerability identified as critical has been detected in getgrav API Plugin up to 1.0.5. Affected by this issue is the function UsersController::createApiKey/generate2fa/disable2fa of the component UsersController. The manipulation leads to improper privilege management.
This vulnerability is referenced as CVE-2026-62666. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.VulDB Recent EntriesRead More