{"apiVersion":"1.0","identifier":"CVE-2026-75832","description":"The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a missing authorization vulnerability in BlueprintPathResolver::resolveUserScope(). The method gates the users/<name> scope on the account-s raw super-admin ACL flag (access.api.super) instead of validating the presented API key-s actual scope. An attacker holding an API key scoped only to api.media.write minted on a super-admin account can bypass the authorization check and, via POST /blueprint-upload or GET /blueprint-files, write a file into another user-s scope (in the shared user/accounts/ directory, constrained to image extensions by assertSafeExtension()) and browse that scope-s file listing, despite the key not being granted api.users.write.","publishedAt":"2026-08-18T12:19:33","lastModifiedAt":"2026-08-19T15:18:08","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-75832","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","epssProbability":0.00222,"riskScore":0.44,"affectedProduct":"grav-plugin-api","affectedVersions":"<1.0.14","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-75832","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-75832","en":"https://www.redsauce.net/en/cves/CVE-2026-75832","fr":"https://www.redsauce.net/fr/cves/CVE-2026-75832","pt":"https://www.redsauce.net/pt/cves/CVE-2026-75832","de":"https://www.redsauce.net/de/cves/CVE-2026-75832","sk":"https://www.redsauce.net/sk/cves/CVE-2026-75832","el":"https://www.redsauce.net/el/cves/CVE-2026-75832"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-75832"}}