High severity8.5NVD Advisory· Published Jul 23, 2026· Updated Aug 28, 2026
CVE-2026-65895
CVE-2026-65895
Description
Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable credential brute-forcing attacks and reconfigure CORS policies to include attacker-controlled origins with credentials enabled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.0.10
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.