CVE-2026-42843 Details
Description
Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configuration, users, and system management. Prior to 1.0.0-beta.15, an insecure direct object reference and logic flaw in the Grav API plugin (UsersController::update) allows any authenticated user with basic API access (api.access) to modify their own permission configuration. An attacker can exploit this to escalate their privileges to Super Administrator (admin.super and api.super), leading to full system compromise and potential RCE. This vulnerability is fixed in 1.0.0-beta.15.
A vulnerability in the Grav API Plugin for Grav CMS, prior to version 1.0.0-beta.15, allows authenticated users with basic API access to exploit an insecure direct object reference in the UsersController's update method. This flaw enables users to modify their own permission settings, potentially escalating their privileges to Super Administrator. Such an escalation could lead to a complete system compromise and, according to the CVE, remote code execution. The vulnerability arises because the access field, which controls user roles and permissions, is improperly validated, allowing low-privileged users to overwrite their access rights.
Users are advised to update the Grav API Plugin to version 1.0.0-beta.15 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/getgrav/grav/security/advisories/GHSA-r945-h4vm-h736 | CISA-ADP | ExploitVendor Advisory |
| https://github.com/getgrav/grav/security/advisories/GHSA-r945-h4vm-h736 | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| getgrav grav-plugin-api | 1.0.0 beta1 1.0.0 beta10 1.0.0 beta11 1.0.0 beta12 1.0.0 beta13 1.0.0 beta14 1.0.0 beta2 1.0.0 beta3 1.0.0 beta4 1.0.0 beta5 1.0.0 beta6 1.0.0 beta7 1.0.0 beta8 1.0.0 beta9 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 27, 2026 | Initial Analysis | [email protected] |
| May 11, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | New CVE Received | [email protected] |