MEDIUM
Trilby Media
CVE published 2026-08-07
CVE-2026-11430
The Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability. When the webhook feature is enabled but no webhookToken is configured, an unauthenticated remote attacker can trigger scheduled jobs by sending a POST request to /scheduler/webhook. The attacker controls when the jobs run and which one runs, but not what the jobs do. Code execution follows only when the operator has con [truncated]