Junglewise Threat Intelligence

CVE-2026-62386: Grav API plugin sensitive information disclosure via JWT in query string

CVE-2026-62386 · Severity: high · CVSS 7.5 · Published 2026-07-17

Vendors: Getgrav.

Executive brief

The Grav API plugin, which provides programmatic access to the Grav content management system, contains a flaw that exposes administrative login tokens. These sensitive tokens are transmitted in website addresses (URLs), causing them to be recorded in plain text within server logs, browser histories, and web proxies. An attacker who gains access to these logs can hijack administrative sessions to steal user data, modify site configurations, or delete website content.

Technical details

The Grav API plugin's JwtAuthenticator::extractBearerToken method implemented a fallback mechanism that accepted JWT access tokens through the '?token=' URL query parameter for all API routes. Because these tokens are part of the request URI, they are stored in plaintext in web server (e.g., Apache) access logs, browser history, and upstream proxy/CDN logs, and are transmitted via the Referer header. A remote attacker with access to any of these logging locations can retrieve a valid admin token. This token can then be used to perform unauthorized actions, including reading system configurations, creating new administrative users, or deleting pages. The issue is addressed in version 1.0.0-rc.16.

Affected products

  • getgrav Grav API plugin (grav-plugin-api) < 1.0.0-rc.16

Timeline

  • 2026-06-30: advisory: Vendor advisory published on GitHub
  • 2026-07-16: disclosed: NVD and VulnCheck publication date
  • 2026-07-16: patched: Fix released in version 1.0.0-rc.16

References