Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 18 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in userPassesAuthorize() (AbstractApiController.php). The function fails to consult the calling request's API key scopes, relying instead on the account's raw super-admin flag and ACL grants. As a result, an authenticated attacker holding a scoped API key minted on a privileged account can bypass their declared scope restrictions to access authorize-gated UI metadata and item definitions (sidebar/menubar/widget items and users-list columns/row-actions/filter-tabs) that their key scope should deny, resulting in information disclosure. | |
| Title | Grav API Plugin before 1.0.14 Missing Authorization | |
| First Time appeared |
Getgrav
Getgrav grav |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Getgrav
Getgrav grav |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-18T11:19:45.775Z
Reserved: 2026-08-18T10:57:39.580Z
Link: CVE-2026-75835
No data.
Status : Received
Published: 2026-08-18T12:19:33.647
Modified: 2026-08-18T12:19:33.647
Link: CVE-2026-75835
No data.
OpenCVE Enrichment
No data.
-
CWE-862
Missing Authorization