CVE-2026-75832: Missing Authorization in getgrav grav
CVE-2026-75832 is a critical missing authorization vulnerability in the Grav API plugin (getgrav/grav-plugin-api) before version 1.0.15. The flaw exists in the BlueprintPathResolver::resolveUserScope() method, which incorrectly authorizes access based on the super-admin ACL flag of the account rather than the actual API key scope. This allows an attacker with an API key scoped only to api.media.write but minted on a super-admin account to write files into another user's scope and browse that user's file listings, despite lacking explicit api.users.write permissions.
AI Analysis
Technical Summary
The Grav API plugin prior to version 1.0.15 contains a missing authorization vulnerability in the BlueprintPathResolver::resolveUserScope() method. This method gates access to the users/<name> scope based on the raw super-admin ACL flag (access.api.super) of the account rather than validating the API key's actual scope. Consequently, an attacker possessing an API key limited to api.media.write but created on a super-admin account can bypass authorization checks. This enables the attacker to write files into another user's scope within the shared user/accounts/ directory (restricted to image extensions) via POST /blueprint-upload and to browse that user's file listings via GET /blueprint-files, even though the key does not have api.users.write permission.
Potential Impact
An attacker with an API key scoped only to api.media.write but minted on a super-admin account can bypass authorization controls to write files into other users' scopes and browse their file listings. This unauthorized file write and directory browsing could lead to unauthorized data exposure or manipulation within the shared user/accounts/ directory. The vulnerability has a CVSS 4.0 score of 9.3, indicating critical severity with network attack vector, no required privileges or user interaction, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A fix is available in Grav API plugin version 1.0.15. Users should upgrade to version 1.0.15 or later to remediate this vulnerability. No additional mitigation steps are indicated beyond applying the official patch.
CVE-2026-75832: Missing Authorization in getgrav grav
Description
CVE-2026-75832 is a critical missing authorization vulnerability in the Grav API plugin (getgrav/grav-plugin-api) before version 1.0.15. The flaw exists in the BlueprintPathResolver::resolveUserScope() method, which incorrectly authorizes access based on the super-admin ACL flag of the account rather than the actual API key scope. This allows an attacker with an API key scoped only to api.media.write but minted on a super-admin account to write files into another user's scope and browse that user's file listings, despite lacking explicit api.users.write permissions.
CVSS v4.0
Score 9.3critical
Affected software
getgrav
grav
pkg:github/getgrav/grav-plugin-apiRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Grav API plugin prior to version 1.0.15 contains a missing authorization vulnerability in the BlueprintPathResolver::resolveUserScope() method. This method gates access to the users/<name> scope based on the raw super-admin ACL flag (access.api.super) of the account rather than validating the API key's actual scope. Consequently, an attacker possessing an API key limited to api.media.write but created on a super-admin account can bypass authorization checks. This enables the attacker to write files into another user's scope within the shared user/accounts/ directory (restricted to image extensions) via POST /blueprint-upload and to browse that user's file listings via GET /blueprint-files, even though the key does not have api.users.write permission.
Potential Impact
An attacker with an API key scoped only to api.media.write but minted on a super-admin account can bypass authorization controls to write files into other users' scopes and browse their file listings. This unauthorized file write and directory browsing could lead to unauthorized data exposure or manipulation within the shared user/accounts/ directory. The vulnerability has a CVSS 4.0 score of 9.3, indicating critical severity with network attack vector, no required privileges or user interaction, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A fix is available in Grav API plugin version 1.0.15. Users should upgrade to version 1.0.15 or later to remediate this vulnerability. No additional mitigation steps are indicated beyond applying the official patch.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-18T10:57:39.580Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a844366c6e8be03322294f2
Added to database: 08/18/2026, 11:35:02 UTC
Last enriched: 09/11/2026, 23:16:43 UTC
Last updated: 10/02/2026, 02:46:06 UTC
Views: 38
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.