CRITICAL 9.8 CVE-2026-80203 Published 26 Aug 2026

Grav Plugin API Key Scope Bypass

Worried this affects one of your servers?

The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope properly.

This allows an API key with limited super authority to perform actions on other super-admin accounts.

  • Impact: Unauthorized access to user management functions

Reference: CVE-2026-80203 on NVD

← Back to Security News