CVE-2026-65897: Getgrav Grav
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invited accounts to groups that grant api.super permissions. Attackers can create invitation records with elevated group membership, and when accepted, the new account gains full super-admin API access without the inviter holding those permissions.
Affected products
- Getgrav Grav: before 1.0.10 (fixed in 1.0.10)
Published 2026-07-23. Last modified 2026-08-28.