PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-80203 getgrav CVE debrief

The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. This critical vulnerability allows an API key scoped below full super authority but belonging to a super-admin account to act against other super-admin accounts, potentially disabling their 2FA, deleting their avatar, minting new API keys under their identity, or deleting their existing API keys. Organizations using getgrav/grav-plugin-api, especially those with super-admin accounts, should be aware of this issue and take immediate action to update and restrict API key scopes. Evidence is limited; further verification is recommended. Limited source detail suggests that defenders should verify API key scopes, review user-management endpoints, and monitor for suspicious activity.

Vendor
getgrav
Product
grav
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-26
Original CVE updated
2026-09-03
Advisory published
2026-08-26
Advisory updated
2026-09-03

Who should care

Organizations using getgrav/grav-plugin-api, especially those with super-admin accounts, should be aware of this critical API-key scope enforcement issue and take immediate action to update and restrict API key scopes. Affected operators, platforms, and security teams should prioritize updating to version 1.0.18 or later and review compensating controls for exposed systems while remediation is scheduled and verified. Vulnerability management and security teams should monitor for suspicious API activity and implement additional security measures to prevent exploitation. Asset inventory and change management processes should be reviewed to ensure that affected systems are identified and remediated promptly. Rollback and change window procedures should be updated to address potential issues with API key scopes. Source tracking and monitoring should be implemented to detect and respond to potential security incidents. This issue requires immediate attention from security teams and operators to prevent potential security breaches. Security teams should also review and restrict API key scopes to prevent unauthorized access to sensitive user-management endpoints. Compensating controls, such as monitoring and detection, should be implemented to address potential security gaps while remediation is in progress. Asset inventory and change management processes should be reviewed to ensure that affected systems are identified and remediated promptly. Rollback and change window procedures should be updated to address potential issues with API key scopes. Source tracking and monitoring should be implemented to detect and respond to potential security incidents. This issue requires immediate attention from security teams and operators to prevent potential security breaches. Security teams should also review and restrict API key scopes to prevent unauthorized access to sensitive user-management endpoints. Compensating controls, such as monitoring and detection, should be implemented to address potential security gaps while remediation is in progress. Asset inventory and change management processes should be reviewed to ensure that affected systems are identified and remediated.

Technical summary

The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. An API key scoped below full super authority but belonging to a super-admin account can act against other super-admin accounts, potentially disabling their 2FA, deleting their avatar, minting new API keys under their identity, or deleting their existing API keys. This issue affects organizations using getgrav/grav-plugin-api, especially those with super-admin accounts.

Defensive priority

Organizations using getgrav/grav-plugin-api should prioritize updating to version 1.0.18 or later to address the API-key scope enforcement issue.

Recommended defensive actions

  • Update getgrav/grav-plugin-api to version 1.0.18 or later
  • Review and restrict API key scopes
  • Monitor for suspicious API activity
  • Implement compensating controls for sensitive user-management endpoints
  • Review asset inventory and change management processes
  • Update rollback and change window procedures
  • Implement source tracking and monitoring

Evidence notes

The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. Evidence is limited; further verification is recommended. Limited source detail suggests that defenders should verify API key scopes, review user-management endpoints, and monitor for suspicious activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-80203 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-80203

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-80203 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80203

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.