Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with a scoped api.config.write key can inject arbitrary commands into scheduler.custom_jobs that execute via Symfony Process for remote code execution.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with a scoped api.config.write key can inject arbitrary commands into scheduler.custom_jobs that execute via Symfony Process for remote code execution. | |
| Title | Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass | |
| First Time appeared |
Getgrav
Getgrav grav |
|
| Weaknesses | CWE-269 | |
| CPEs | cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Getgrav
Getgrav grav |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-14T11:35:37.166Z
Reserved: 2026-08-10T15:12:59.509Z
Link: CVE-2026-72830
No data.
Status : Received
Published: 2026-08-14T12:16:46.277
Modified: 2026-08-14T12:16:46.277
Link: CVE-2026-72830
No data.
OpenCVE Enrichment
No data.