Skip to content
Threat Feed
critical advisory

Authorization Bypass in grav-plugin-api

The grav-plugin-api plugin for Grav CMS (before version 1.0.18) contains an authorization flaw in UsersController.php that allows API keys with restricted scopes to perform sensitive administrative actions against super-admin accounts.

CVE search metadata

CVE search record: CVE-2026-80203. Severity: critical. CVSS: 9.8. KEV: no. Product: grav-plugin-api. Brief: Authorization Bypass in grav-plugin-api. Brief link: https://feed.craftedsignal.io/briefs/2026-08-grav-plugin-auth-bypass/

The Grav CMS plugin grav-plugin-api, specifically versions prior to 1.0.18, contains a critical authorization vulnerability (CVE-2026-80203) within the UsersController.php file. The vulnerability stems from the requireNotSuperTarget() function, which incorrectly validates the authorization scope of API keys.

Instead of verifying if a specific API key possesses the required authority via isSuperWithinScope(), the function checks if the acting user account has global super-admin status. Consequently, an attacker holding a compromised or limited API key associated with a super-admin account can bypass intended scoping restrictions. This allows the attacker to execute unauthorized administrative actions - such as disabling multi-factor authentication (2FA), modifying or deleting avatars, and managing (minting or deleting) other API keys - against other super-admin accounts. The issue affects seven distinct user-management endpoints, posing a severe risk to administrative control and account integrity within Grav CMS environments.

Impact

Successful exploitation allows for unauthorized account management, potential privilege escalation, and loss of administrative account security. Affected organizations face the risk of account takeover and 2FA bypass for highly privileged administrative users. Given the nature of the vulnerability, an attacker who gains access to a scoped API key belonging to a super-admin can effectively compromise the entire administrative infrastructure of the Grav CMS instance.

Recommendation

  • Upgrade the grav-plugin-api plugin to version 1.0.18 or higher across all production Grav CMS instances.
  • Audit existing API key scopes and permissions for all accounts with administrative privileges to identify keys that may have been misused.
  • Review web server access logs for anomalous activity directed at user-management API endpoints, specifically searching for unauthorized requests originating from existing API keys.
  • Revoke any API keys suspected of being used for unauthorized administrative changes.

Immediate actions

Upgrade grav-plugin-api to 1.0.18

IT Operations 24h