Ghostwire

CVE-2026-72830: Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates,...

CRITICAL CVSS 0.0

Published: August 14, 2026 | Last Modified: August 14, 2026

Description

Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with a scoped api.config.write key can inject arbitrary commands into scheduler.custom_jobs that execute via Symfony Process for remote code execution.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References