← Πίσω στην αναζήτηση CVE

CVE-2026-75835

Grav API plugin

Περιγραφή

Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in userPassesAuthorize() (AbstractApiController.php). The function fails to consult the calling request-s API key scopes, relying instead on the account-s raw super-admin flag and ACL grants. As a result, an authenticated attacker holding a scoped API key minted on a privileged account can bypass their declared scope restrictions to access authorize-gated UI metadata and item definitions (sidebar/menubar/widget items and users-list columns/row-actions/filter-tabs) that their key scope should deny, resulting in information disclosure.

CVSS 4.3EPSS 0.22399999999999998%Κίνδυνος 0.44
Προβολή πηγής
Δημοσίευση
2026-08-18 12:19:33
Επηρεαζόμενες εκδόσεις
<1.0.14
Τύπος
Βιβλιοθήκη
Τελευταία τροποποίηση
2026-08-18 15:17:14
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N