CVE-2026-42843

EUVD-2026-29128
Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configuration, users, and system management. Prior to 1.0.0-beta.15, an insecure direct object reference and logic flaw in the Grav API plugin (UsersController::update) allows any authenticated user with basic API access (api.access) to modify their own permission configuration. An attacker can exploit this to escalate their privileges to Super Administrator (admin.super and api.super), leading to full system compromise and potential RCE. This vulnerability is fixed in 1.0.0-beta.15.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 26%
Affected Products (NVD)
VendorProductVersion
getgravgrav-plugin-api
1.0.0:beta1
getgravgrav-plugin-api
1.0.0:beta10
getgravgrav-plugin-api
1.0.0:beta11
getgravgrav-plugin-api
1.0.0:beta12
getgravgrav-plugin-api
1.0.0:beta13
getgravgrav-plugin-api
1.0.0:beta14
getgravgrav-plugin-api
1.0.0:beta2
getgravgrav-plugin-api
1.0.0:beta3
getgravgrav-plugin-api
1.0.0:beta4
getgravgrav-plugin-api
1.0.0:beta5
getgravgrav-plugin-api
1.0.0:beta6
getgravgrav-plugin-api
1.0.0:beta7
getgravgrav-plugin-api
1.0.0:beta8
getgravgrav-plugin-api
1.0.0:beta9
𝑥
= Vulnerable software versions