GHSA-qrm9-ppgh-qwm9HighCVSS 8.8

grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa,...

Published
July 17, 2026
Last Modified
July 17, 2026

🔗 CVE IDs covered (1)

📋 Description

grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, allowing non-super api.users.write managers to escalate to super-admin. Attackers can mint API keys bound to super-admin accounts or strip 2FA from super-admin users to achieve full instance takeover.

🔗 References (4)