{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/scheduler-webhook/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-11430"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["scheduler-webhook"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Grav CMS"],"content_html":"\u003cp\u003eCVE-2026-11430 identifies an authentication bypass vulnerability within the scheduler-webhook plugin for Grav CMS. The flaw originates from a short-circuiting conditional statement in the plugin's token validation logic. When the webhook feature is enabled (via \u003ccode\u003escheduler.modern.webhook.enabled\u003c/code\u003e set to true) but a \u003ccode\u003ewebhookToken\u003c/code\u003e is not explicitly configured, the validation routine is skipped entirely.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated remote attacker can exploit this by sending a crafted POST request to the \u003ccode\u003e/scheduler/webhook\u003c/code\u003e endpoint. While the attacker cannot inject arbitrary code, they can force the execution of already-configured scheduled jobs, including those that execute system commands. The impact is limited by the existing server configuration, as the attacker can control the execution timing and select which pre-existing job to trigger, but cannot define the initial task payload. This vulnerability is not present in default Grav installations, as it requires the manual installation of the plugin and specific misconfiguration.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to trigger administrative scheduled tasks on the affected server. Depending on the configured jobs, this could lead to unauthorized system command execution, denial of service through resource exhaustion, or the manipulation of application state. The vulnerability affects instances where the scheduler-webhook plugin is enabled without a security token.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately audit Grav CMS installations to identify instances where the \u003ccode\u003escheduler-webhook\u003c/code\u003e plugin is enabled.\u003c/li\u003e\n\u003cli\u003eEnsure a strong \u003ccode\u003ewebhookToken\u003c/code\u003e is configured for any enabled webhooks to prevent the short-circuiting logic from bypassing validation.\u003c/li\u003e\n\u003cli\u003eReview all configured scheduled jobs for the \u003ccode\u003escheduler-webhook\u003c/code\u003e plugin to ensure they do not perform sensitive operations if triggered by unauthorized parties.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests targeting the \u003ccode\u003e/scheduler/webhook\u003c/code\u003e path, particularly those containing the \u003ccode\u003ejob\u003c/code\u003e parameter.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-07T19:34:53Z","date_published":"2026-08-07T19:34:53Z","id":"https://feed.craftedsignal.io/briefs/2026-08-grav-cms-auth-bypass/","summary":"An authentication bypass in the Grav CMS scheduler-webhook plugin allows unauthenticated attackers to trigger pre-configured scheduled jobs via the /scheduler/webhook endpoint.","title":"Authentication Bypass in Grav CMS scheduler-webhook Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-grav-cms-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Scheduler-Webhook","version":"https://jsonfeed.org/version/1.1"}