Unrated severityNVD Advisory· Published Jul 23, 2026· Updated Jul 24, 2026
Grav API Plugin before 1.0.10 Broken Access Control
CVE-2026-65895
Description
Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable credential brute-forcing attacks and reconfigure CORS policies to include attacker-controlled origins with credentials enabled.
Affected products
2- Range: <1.0.10
Patches
Vulnerability mechanics
References
3- github.com/getgrav/grav/commit/f9438d4e71389b1041ac60b69b0b5714ecfa3bddmitrepatch
- github.com/getgrav/grav/security/advisories/GHSA-4pqv-2qj5-38fpmitrevendor-advisory
- www.vulncheck.com/advisories/grav-api-plugin-before-broken-access-controlmitrethird-party-advisory
News mentions
0No linked articles in our index yet.