CVE-2026-42843Disclosure(getgrav / grav-plugin-api)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configuration, users, and system management. Prior to 1.0.0-beta.15, an insecure direct object reference and logic flaw in the Grav API plugin (UsersController::update) allows any authenticated user with basic API access (api.access) to modify their own permission configuration. An attacker can exploit this to escalate their privileges to Super Administrator (admin.super and api.super), leading to full system compromise and potential RCE. This vulnerability is fixed in 1.0.0-beta.15.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • grav-plugin-api

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
grav-plugin-api

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-11: 105-11
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVE@CVEnew
    Disclosure

    CVE-2026-42843 Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configuration, users, and system management. Prior to … https://www.cve.org/CVERecord?id=CVE-2026-42843

    Post summary

    The passage presents a brief disclosure of CVE‑2026‑42843, noting that the Grav API Plugin exposes extensive site controls via a RESTful interface; it contains no PoC, exploit, or mitigation details.

    00000118
    57.5K followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
Appgetgravgrav-plugin-api1.0.0--
Appgetgravgrav-plugin-api1.0.0--
Appgetgravgrav-plugin-api1.0.0--
Appgetgravgrav-plugin-api1.0.0--
Appgetgravgrav-plugin-api1.0.0--
Appgetgravgrav-plugin-api1.0.0--
Appgetgravgrav-plugin-api1.0.0--
Appgetgravgrav-plugin-api1.0.0--
Appgetgravgrav-plugin-api1.0.0--
Appgetgravgrav-plugin-api1.0.0--
Appgetgravgrav-plugin-api1.0.0--
Appgetgravgrav-plugin-api1.0.0--
Appgetgravgrav-plugin-api1.0.0--
Appgetgravgrav-plugin-api1.0.0--

Explore more