Authentication Scope Bypass in Grav API Plugin Leading to RCE
An API key scope-cap bypass in the Grav API plugin allows attackers with restricted keys to execute server-side templates via Server-Side Template Injection.
CVE search metadata
CVE search record: CVE-2026-72824. Severity: critical. CVSS: 9.8. KEV: no. Product: grav-plugin-api (< 1.0.13), grav-plugin-api (< 1.0.15), grav-plugin-api. Brief: Authentication Scope Bypass in Grav API Plugin Leading to RCE. Brief link: https://feed.craftedsignal.io/briefs/2026-08-grav-api-bypass/
What's new
The Grav API plugin (getgrav/grav-plugin-api) version 1.0.13 and earlier contains a critical authorization vulnerability within the PagesController::guardTwigContent() method. The vulnerability stems from the plugin's failure to validate API key scopes when performing Twig-toggle checks. Specifically, the system utilizes a bare isSuperAdmin() gate instead of consulting the associated api_key_scopes.
This flaw allows an attacker possessing an API key restricted to api.pages.write - provided it was minted on a super account - to override authorization controls and enable process.twig during page save operations. If the target Grav instance has security.twig_content.process_enabled set to true and editor_enabled set to false, an attacker can leverage this bypass to inject arbitrary Twig tags. This leads to Server-Side Template Injection (SSTI), granting the attacker the ability to execute code on the underlying host server. This vulnerability is significant for organizations relying on Grav API for content management as it effectively turns a restricted write operation into full system compromise.
Impact
The vulnerability results in unauthenticated or low-privilege Remote Code Execution (RCE) on the server hosting Grav CMS. If successfully exploited, an attacker gains the ability to execute arbitrary commands, read sensitive server files, and potentially move laterally within the network. This affects all installations of the Grav API plugin version 1.0.12 and below where the specified Twig processing configurations are active.
Recommendation
- Upgrade the Grav API plugin to version 1.0.13 or higher immediately to apply the patch for CVE-2026-72824.
- Audit all active API keys in the Grav environment to verify scopes and reduce the number of keys minted on super-administrator accounts.
- Review the configuration file for security.twig_content.process_enabled and ensure it is set to false unless Twig-in-content functionality is strictly required for the business operation.
- Monitor web server logs for HTTP requests directed at the PagesController or save-page endpoints containing unexpected Twig syntax (e.g., {{ ... }} or {% ... %}) in content fields.
Immediate actions
Upgrade Grav API plugin to 1.0.13
Mitigations
Disable security.twig_content.process_enabled in Grav configuration
CVE-2026-72824
Detection coverage 1
Detect CVE-2026-75830 Exploitation - Path Traversal in grav-plugin-api
highDetects exploitation attempts against CVE-2026-75830 where a user provides directory traversal sequences in the suffix parameter of the batch copy API endpoint.
Detection queries are available on the platform. Get full rules →