THREAT OPS › Threat News › [NVD] CVE-2026-80203 (CRITICAL 9.8) — The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses isSuperAdmin() on the acting account rather than verifying whether the s
[NVD] CVE-2026-80203 (CRITICAL 9.8) — The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses isSuperAdmin() on the acting account rather than verifying whether the s
CVE-2026-80203 CVSS: 9.8 CRITICAL Published: 2026-08-26T11:16:39.647
The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses isSuperAdmin() on the acting account rather than verifying whether the specific API key carries super authority (via isSup
Indicators of compromise
- CVE-2026-80203cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-80203