CVE-2026-65007: Grav API Plugin Broken Authorization Allows API Key Takeover
ID: 6dac9783-2cb2-5b55-bcc8-5848161a8380
STIX ID: report--6dac9783-2cb2-5b55-bcc8-5848161a8380
Feed Name: CosmicBytez Labs
A critical broken-authorization vulnerability (CVE-2026-65007, CVSS 9.6) in the Grav CMS API plugin (grav-plugin-api < 1.0.8) allows any authenticated user with only the baseline admin.login permission to generate or revoke API keys for other accounts — including superadmins — before the full account-management ACL runs; the advisory includes an exploit scenario, technical analysis, detection indicators, and remediation steps (upgrade to 1.0.8, audit and rotate API keys, or disable the plugin/WAF restrictions if immediate patching is not possible).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
