Skip to content
Threat Feed
high advisory

Authentication Scope Bypass in Grav API Plugin Leading to RCE

An API key scope-cap bypass in the Grav API plugin allows attackers with restricted keys to execute server-side templates via Server-Side Template Injection.

CVE search metadata

CVE search record: CVE-2026-72824. Severity: critical. CVSS: 9.8. KEV: no. Product: grav-plugin-api (< 1.0.13), grav-plugin-api (< 1.0.15), grav-plugin-api. Brief: Authentication Scope Bypass in Grav API Plugin Leading to RCE. Brief link: https://feed.craftedsignal.io/briefs/2026-08-grav-api-bypass/

What's new

  • 1. added detection rule: Detect CVE-2026-75830 Exploitation - Path Traversal in grav-plugin-api Aug 18, 12:53 via nvd
  • 2. added coverage for grav-plugin-api (< 1.0.15) Aug 18, 12:53 via nvd

The Grav API plugin (getgrav/grav-plugin-api) version 1.0.13 and earlier contains a critical authorization vulnerability within the PagesController::guardTwigContent() method. The vulnerability stems from the plugin's failure to validate API key scopes when performing Twig-toggle checks. Specifically, the system utilizes a bare isSuperAdmin() gate instead of consulting the associated api_key_scopes.

This flaw allows an attacker possessing an API key restricted to api.pages.write - provided it was minted on a super account - to override authorization controls and enable process.twig during page save operations. If the target Grav instance has security.twig_content.process_enabled set to true and editor_enabled set to false, an attacker can leverage this bypass to inject arbitrary Twig tags. This leads to Server-Side Template Injection (SSTI), granting the attacker the ability to execute code on the underlying host server. This vulnerability is significant for organizations relying on Grav API for content management as it effectively turns a restricted write operation into full system compromise.

Impact

The vulnerability results in unauthenticated or low-privilege Remote Code Execution (RCE) on the server hosting Grav CMS. If successfully exploited, an attacker gains the ability to execute arbitrary commands, read sensitive server files, and potentially move laterally within the network. This affects all installations of the Grav API plugin version 1.0.12 and below where the specified Twig processing configurations are active.

Recommendation

  • Upgrade the Grav API plugin to version 1.0.13 or higher immediately to apply the patch for CVE-2026-72824.
  • Audit all active API keys in the Grav environment to verify scopes and reduce the number of keys minted on super-administrator accounts.
  • Review the configuration file for security.twig_content.process_enabled and ensure it is set to false unless Twig-in-content functionality is strictly required for the business operation.
  • Monitor web server logs for HTTP requests directed at the PagesController or save-page endpoints containing unexpected Twig syntax (e.g., {{ ... }} or {% ... %}) in content fields.

Immediate actions

Upgrade Grav API plugin to 1.0.13

IT Operations 24h

Mitigations

Disable security.twig_content.process_enabled in Grav configuration

immediate IT Operations

CVE-2026-72824

Detection coverage 1

Detect CVE-2026-75830 Exploitation - Path Traversal in grav-plugin-api

high

Detects exploitation attempts against CVE-2026-75830 where a user provides directory traversal sequences in the suffix parameter of the batch copy API endpoint.

sigma tactics: initial_access, persistence techniques: T1059 sources: webserver

Detection queries are available on the platform. Get full rules →