CVE-2026-57852 Details
Description
Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured scheduled jobs by exploiting a short-circuit logic flaw in the webhook token validation. Attackers can send a single unauthenticated POST request to the scheduler webhook endpoint to execute all configured scheduled jobs or target a specific job, causing unintended execution of operator-defined commands under the web server process user.
An authentication bypass vulnerability has been identified in the Grav CMS scheduler-webhook plugin, versions through 1.1.1. This vulnerability allows unauthenticated remote attackers to trigger scheduled jobs by exploiting a flaw in the webhook token validation process. The issue arises because the token check short-circuits when no token is configured, which is the default state. As a result, all scheduled jobs are executed, potentially leading to unauthorized execution of commands under the web server process user.
Users can upgrade to Grav CMS version 2.0.9 and the Grav Scheduler Webhook Plugin version 1.1.3 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 20, 2026CISA-ADP
Assessed Jul 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/getgrav/grav | [email protected] | ProductSource CodeVendor |
| https://github.com/getgrav/grav/security/advisories/GHSA-xwv3-2mv2-w33x | [email protected] | AdvisoryExploitTechnical AnalysisVendor |
| https://www.vulncheck.com/advisories/authentication-bypass-via-null-short-circuit-in-grav-cms-scheduler-webhook-token-check | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-303 | Incorrect Implementation of Authentication Algorithm | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Grav CMS | <= 2.0.8 (semver) |
CPE
Remediation
| |
| Grav CMS scheduler-webhook | <= 1.1.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Modified | CISA-ADP |
| Jul 20, 2026 | New CVE Received | [email protected] |
Volerion