{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/grav-cms/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.5,"id":"CVE-2026-65895"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Grav API Plugin (versions before 1.0.10)"],"_cs_severities":["high"],"_cs_tags":["grav-cms","api-plugin","vulnerability","access-control","cwe-862"],"_cs_type":"advisory","_cs_vendors":["Grav"],"content_html":"\u003cp\u003eCVE-2026-65895 identifies a critical missing authorization vulnerability within Grav API Plugin versions prior to 1.0.10. This flaw allows authenticated users who possess the \u003ccode\u003eapi.config.write\u003c/code\u003e privilege to bypass intended access controls and modify security-critical configurations. Specifically, an attacker can disable the site's rate limiting feature, paving the way for credential brute-forcing attacks. Furthermore, the vulnerability enables the modification of Cross-Origin Resource Sharing (CORS) policies, allowing an attacker to include their own controlled origins with credentials enabled. This manipulation can lead to unauthorized access to sensitive data and credentials, impacting the integrity and confidentiality of the Grav installation and its users. The vulnerability carries a CVSS v3.1 Base Score of 8.5 (High), emphasizing its significant potential impact.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker gains authenticated access to a Grav instance, potentially through compromised credentials or other means.\u003c/li\u003e\n\u003cli\u003eThe attacker's account possesses the \u003ccode\u003eapi.config.write\u003c/code\u003e privilege, which is overly broad due to CVE-2026-65895 and allows modification of critical settings.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts and sends an API request to the Grav instance, targeting the rate limiting configuration endpoint.\u003c/li\u003e\n\u003cli\u003eLeveraging the missing authorization vulnerability, the attacker successfully disables site-wide rate limiting, bypassing intended security restrictions.\u003c/li\u003e\n\u003cli\u003eSubsequently, the attacker sends another API request to reconfigure the Cross-Origin Resource Sharing (CORS) policies of the Grav instance.\u003c/li\u003e\n\u003cli\u003eThe attacker adds attacker-controlled origins to the CORS policy, enabling the inclusion of credentials and circumventing the browser's same-origin policy.\u003c/li\u003e\n\u003cli\u003eWith rate limiting disabled, the attacker can now perform high-volume credential brute-forcing attempts against other user accounts on the Grav instance.\u003c/li\u003e\n\u003cli\u003eThe manipulated CORS policies facilitate unauthorized access to sensitive data and credentials from victim browsers interacting with the compromised Grav instance.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eIf successfully exploited, CVE-2026-65895 enables severe consequences for affected Grav instances. The ability to disable rate limiting allows attackers to launch efficient, high-volume credential brute-forcing attacks, potentially leading to the compromise of additional user accounts. Reconfiguring CORS policies permits unauthorized cross-origin requests, leading to data exfiltration, session hijacking, and other web-based attacks that compromise the confidentiality of user information. The vulnerability could result in widespread account compromise and unauthorized data access across the platform.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch Grav API Plugin immediately to version 1.0.10 or later to address CVE-2026-65895.\u003c/li\u003e\n\u003cli\u003eReview Grav access control policies to ensure that only trusted administrators have the \u003ccode\u003eapi.config.write\u003c/code\u003e privilege.\u003c/li\u003e\n\u003cli\u003eMonitor Grav API logs for any unauthorized or suspicious modifications to rate limiting and CORS configuration settings.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T12:22:35Z","date_published":"2026-07-23T12:22:35Z","id":"https://feed.craftedsignal.io/briefs/2026-07-grav-api-auth-bypass/","summary":"Grav API Plugin versions prior to 1.0.10 contain a missing authorization vulnerability (CVE-2026-65895) allowing authenticated users with the 'api.config.write' privilege to modify critical security settings, including disabling site-wide rate limiting to enable credential brute-forcing attacks and reconfiguring CORS policies to include attacker-controlled origins with credentials enabled, potentially leading to unauthorized data access.","title":"Grav API Plugin Missing Authorization Allows Security Settings Modification","url":"https://feed.craftedsignal.io/briefs/2026-07-grav-api-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Grav-Cms","version":"https://jsonfeed.org/version/1.1"}