Executive brief
The Grav API plugin, which provides remote access to manage Grav CMS content and users, contains a flaw that allows standard users to change their own account permissions. By sending a specially crafted request, a user with basic access can grant themselves 'Super Administrator' status. This allows an attacker to take complete control of the website, including the ability to steal data, modify site content, or execute malicious code on the underlying server.
Technical details
An insecure direct object reference (IDOR) and logic flaw exist in the `UsersController::update` method of the Grav API plugin. While the plugin allows users to update their own profiles with basic `api.access` permissions, the `$allowedFields` whitelist indiscriminately includes the 'access' field. An attacker can submit a PATCH request to the `/api/v1/users/{username}` endpoint containing a malicious 'access' object. This allows a low-privileged user to grant themselves `admin.super` and `api.super` permissions, leading to full system compromise and potential Remote Code Execution (RCE) via template manipulation. The issue is fixed in version 1.0.0-beta.15.
Affected products
- Grav Grav API Plugin Prior to 1.0.0-beta.15
Timeline
- 2026-04-27: advisory: GitHub Security Advisory published by vendor
- 2026-05-11: disclosed: CVE published to NVD