CRITICAL
9.8 CVE-2026-80203 Published 26 Aug 2026
Grav Plugin API Key Scope Bypass
Worried this affects one of your servers?
The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope properly.
This allows an API key with limited super authority to perform actions on other super-admin accounts.
- Impact: Unauthorized access to user management functions
Reference: CVE-2026-80203 on NVD
← Back to Security News