External risk intelligence

Grav API Plugin Scope Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-80203

The vulnerability affects an API plugin for a web-based CMS. Grav is a web application commonly deployed as an internet-facing service, and the affected endpoints are part of the application's API surface, which is typically accessible over the network for integration or management purposes.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in a Grav CMS plugin that handles API key permissions. The flaw could allow an improperly scoped API key to perform sensitive administrative actions, even if the key is not intended to have such broad access. The main concern is confirming relevance and exposure of this plugin within your environment.

  • An API plugin incorrectly allows limited keys to perform admin actions.
  • It impacts sensitive user and API key management functions.
  • Focus on confirming if your systems use this plugin.

Attack Path

How an attacker could exploit the issue

An attacker could leverage an existing, but improperly scoped, API key to gain elevated privileges. If an API key belonging to a super-admin account is limited in scope, it can still be used to impersonate that super-admin and perform sensitive actions on other super-admin accounts, such as disabling their multi-factor authentication or deleting their API keys. This could ultimately lead to full administrative control of the affected system.

  • Exposed API key, low scope.
  • Call sensitive user-management endpoints.
  • Full administrative control.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker with a specific type of API key to perform unauthorized administrative actions on user accounts. This is possible when the API key's scope is not properly checked against the user account's privileges for sensitive user management functions.

  • User accounts and their associated data.
  • API keys could be misused to alter accounts.
  • Unauthorized actions could compromise account integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts the `getgrav/grav-plugin-api` plugin, suggesting that teams responsible for the Grav CMS, its plugins, or the underlying web infrastructure are likely involved. Initial steps should focus on identifying all Grav installations, determining their exposure and criticality, and pinpointing the specific application or system owners accountable for the plugin's management and remediation.

  • Identify Grav CMS owners.
  • Verify API endpoint reachability.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the getgrav/grav-plugin-api plugin?

It is an extension for Grav, a flat-file content management system. This specific plugin provides an API layer that allows developers to integrate with or manage the Grav platform programmatically. It is commonly used to automate site administration, manage user accounts, and handle configuration tasks remotely via structured API requests.

What does CWE-863 mean for CVE-2026-80203?

CWE-863 refers to Incorrect Authorization. In this CVE, the plugin fails to verify whether a specific API key actually possesses the required permissions to perform sensitive operations. Instead of checking the key's assigned scope, the system only checks if the underlying user account has administrative status. This allows a key with restricted permissions to perform powerful actions that it should not be authorized to handle.

How can an attacker trigger this vulnerability?

An attacker needs an API key linked to a super-admin account, even if that key is restricted in scope. The bug is triggered when using this key against specific user-management endpoints. Simply having a low-privilege API key belonging to a standard user account will not trigger the vulnerability, as the logic flaw specifically exploits the incorrect association between the super-admin's identity and the API key's limited permissions.

Why does Halo Surface Signal categorize this as external?

Halo Surface Signal labels this as external because Grav is frequently deployed as an internet-facing web application. Since the affected API endpoints are designed for network-based integration and management, they are often reachable over the internet. If your Grav installation's API is exposed to the public network, these sensitive management functions are potentially accessible to unauthorized actors.

What should I do if I run Grav with this plugin?

Start by locating all installations of the Grav CMS within your environment to determine if the vulnerable plugin is active. Once identified, consult your development team to confirm if these API endpoints are currently exposed. Your primary goal is to assess the risk to user management and plan for an update to the plugin, following the vendor’s guidance to secure these endpoints.

References