PatchSiren cyber security CVE debrief
CVE-2026-72823 getgrav CVE debrief
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope cap bypass in DemoController. This vulnerability allows any scoped API key minted on a super account to bypass its scope restrictions when calling the baseline() and reset() operations, potentially leading to demo-engine control issues. Organizations using the Grav API plugin, especially those with demo mode configured and writable resources, should be aware of this vulnerability and take action to patch or mitigate. The CVE record was published on 2026-08-14T12:16:45.397Z and has not been modified since then. To address this issue, it is crucial to understand the implications of the API-key scope cap bypass and the potential impact on demo-engine control.
- Vendor
- getgrav
- Product
- grav
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-14
- Original CVE updated
- 2026-08-31
- Advisory published
- 2026-08-14
- Advisory updated
- 2026-08-31
Who should care
Organizations using the Grav API plugin, especially those with demo mode configured and writable resources, should be aware of this vulnerability and take action to patch or mitigate. This includes reviewing and restricting demo mode configurations, monitoring for suspicious activities, and inventorying Grav API plugin versions in use. Additionally, organizations should prioritize patching to prevent potential demo-engine control issues and consider compensating controls for demo mode.
Technical summary
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope cap bypass in DemoController. Its private requireSuper() method checks isSuperAdmin() and returns early before invoking requirePermission(), so the api_key_scopes cap (enforced only in requirePermission()) is skipped. As a result, any scoped API key minted on a super account can bypass its scope restrictions when calling the baseline() and reset() operations (e.g., POST /api/v1/demo/reset), allowing it to capture the demo baseline or force a demo reset. Impact is bounded to demo-engine control and is conditional on demo mode being configured with writable resources. The vulnerability highlights the importance of proper API key scope enforcement and demo mode configuration.
Defensive priority
Organizations using the Grav API plugin should prioritize patching to prevent potential demo-engine control issues.
Recommended defensive actions
- Patch the Grav API plugin to version 1.0.13 or later
- Review and restrict demo mode configurations to prevent writable resources
- Monitor for suspicious demo-engine control activities
- Inventory and verify Grav API plugin versions in use
- Consider compensating controls for demo mode
- Review official advisory details for additional guidance
- Verify patch deployment in managed environments
Evidence notes
The CVE-2026-72823 issue involves an API-key scope cap bypass in DemoController of the Grav API plugin before version 1.0.13. The private requireSuper() method checks isSuperAdmin() and returns early before invoking requirePermission(), skipping the api_key_scopes cap enforced only in requirePermission(). As a result, any scoped API key minted on a super account can bypass its scope restrictions when calling the baseline() and reset() operations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72823 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72823
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72823 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72823
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/getgrav/grav/security/advisories/GHSA-vq9w-jwj5-wfjg
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/grav-before-api-key-scope-cap-bypass-via-democontroller
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.