CVE-2026-72829Patch

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. These methods enforce the scope cap only for api.users.write, but gate super-privilege grants on a bare isSuperAdmin() check that reads access.api.super directly without consulting the key's scopes. As a result, an api.users.write-scoped key minted on a super account can set access.api.super or assign a super-granting group to mint or promote a full super account, then authenticate as that account for uncapped administrative privileges.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-14: 1Patch / Workaround · 2026-08-14: 1Technical Details · 2026-08-14: 108-14
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • ThreatAft@ThreatAft
    Patch

    🚨 Grav CMS + API Plugin Mass Disclosure — 11 CVEs, FIVE CVSS 9.8 CVE-2026-72829 (9.8): UsersController → super-admin escalation Update Grav to 2.0.13+ and API Plugin to 1.0.13+ NOW. → https://threataft.com/articles/grav-cms-api-plugin-mass-disclosure-11-cves #cybersecurity #infosec #GravCMS #CMS #API #Security #ThreatIntel

    Post summary

    Grav CMS hosts 11 critical CVEs, including CVE‑2026‑72829 which allows super‑admin escalation; users are advised to upgrade Grav to 2.0.13+ and API Plugin to 1.0.13+ to apply the patch.

    0001083
    36 followersView on X

Explore more