Vulnerability Description
grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, allowing non-super api.users.write managers to escalate to super-admin. Attackers can mint API keys bound to super-admin accounts or strip 2FA from super-admin users to achieve full instance takeover.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/getgrav/grav/security/advisories/GHSA-8gg4-rvvv-cq96
- https://www.vulncheck.com/advisories/grav-plugin-api-privilege-escalation-via-cr
FAQ
What is CVE-2026-62233?
CVE-2026-62233 is a vulnerability with a CVSS score of 8.8 (HIGH). grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, allowing non-super api.users.write managers to escalate to super-admin. Attack...
How severe is CVE-2026-62233?
CVE-2026-62233 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-62233?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.