CRITICALVulnerability
CVE-2026-80203
The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses isSuperAdmin() on the acting account rather than verifying whether the specific API key carries super authority (via isSuperWithinScope()). As a result, an API key scoped below full super authority but belonging to a super-admin account can act against other super-admin accounts—disabling their 2FA, deleting their avatar, minting new API keys under their identity, or deleting their existing API keys.
Properties
- severity
- CRITICAL
- score
- 9.8
- epss_score
- 0.00387
- cve_id
- CVE-2026-80203
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- published_at
- 2026-08-26T11:16:39.647
- last_modified
- 2026-09-03T05:15:14.120
- epss_percentile
- 0.31899
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]Incorrect Authorization
Explore deeper with Ninja Signal's threat intelligence graph