PatchSiren cyber security CVE debrief
CVE-2026-80203 getgrav CVE debrief
The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. This critical vulnerability allows an API key scoped below full super authority but belonging to a super-admin account to act against other super-admin accounts, potentially disabling their 2FA, deleting their avatar, minting new API keys under their identity, or deleting their existing API keys. Organizations using getgrav/grav-plugin-api, especially those with super-admin accounts, should be aware of this issue and take immediate action to update and restrict API key scopes. Evidence is limited; further verification is recommended. Limited source detail suggests that defenders should verify API key scopes, review user-management endpoints, and monitor for suspicious activity.
- Vendor
- getgrav
- Product
- grav
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-26
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-08-26
- Advisory updated
- 2026-09-03
Who should care
Organizations using getgrav/grav-plugin-api, especially those with super-admin accounts, should be aware of this critical API-key scope enforcement issue and take immediate action to update and restrict API key scopes. Affected operators, platforms, and security teams should prioritize updating to version 1.0.18 or later and review compensating controls for exposed systems while remediation is scheduled and verified. Vulnerability management and security teams should monitor for suspicious API activity and implement additional security measures to prevent exploitation. Asset inventory and change management processes should be reviewed to ensure that affected systems are identified and remediated promptly. Rollback and change window procedures should be updated to address potential issues with API key scopes. Source tracking and monitoring should be implemented to detect and respond to potential security incidents. This issue requires immediate attention from security teams and operators to prevent potential security breaches. Security teams should also review and restrict API key scopes to prevent unauthorized access to sensitive user-management endpoints. Compensating controls, such as monitoring and detection, should be implemented to address potential security gaps while remediation is in progress. Asset inventory and change management processes should be reviewed to ensure that affected systems are identified and remediated promptly. Rollback and change window procedures should be updated to address potential issues with API key scopes. Source tracking and monitoring should be implemented to detect and respond to potential security incidents. This issue requires immediate attention from security teams and operators to prevent potential security breaches. Security teams should also review and restrict API key scopes to prevent unauthorized access to sensitive user-management endpoints. Compensating controls, such as monitoring and detection, should be implemented to address potential security gaps while remediation is in progress. Asset inventory and change management processes should be reviewed to ensure that affected systems are identified and remediated.
Technical summary
The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. An API key scoped below full super authority but belonging to a super-admin account can act against other super-admin accounts, potentially disabling their 2FA, deleting their avatar, minting new API keys under their identity, or deleting their existing API keys. This issue affects organizations using getgrav/grav-plugin-api, especially those with super-admin accounts.
Defensive priority
Organizations using getgrav/grav-plugin-api should prioritize updating to version 1.0.18 or later to address the API-key scope enforcement issue.
Recommended defensive actions
- Update getgrav/grav-plugin-api to version 1.0.18 or later
- Review and restrict API key scopes
- Monitor for suspicious API activity
- Implement compensating controls for sensitive user-management endpoints
- Review asset inventory and change management processes
- Update rollback and change window procedures
- Implement source tracking and monitoring
Evidence notes
The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. Evidence is limited; further verification is recommended. Limited source detail suggests that defenders should verify API key scopes, review user-management endpoints, and monitor for suspicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-80203 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-80203
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-80203 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80203
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/getgrav/grav/security/advisories/GHSA-94q7-vrqr-cx5v
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/grav-before-1.0.18-authentication-bypass-via-scoped-api-key
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.