CVE-2026-65897
published 2026-07-23CVE-2026-65897: Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to…
PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.52%
42.5th percentile
Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invited accounts to groups that grant api.super permissions. Attackers can create invitation records with elevated group membership, and when accepted, the new account gains full super-admin API access without the inviter holding those permissions.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| getgrav | grav | < 1.0.10 | 1.0.10 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Getgrav Grav Plugin up to 1.0.9 Invitations Controller create groups permission (EUVD-2026-48247)
vuldb·2026-07-25·CVSS 8.8
CVE-2026-65897 [HIGH] Getgrav Grav Plugin up to 1.0.9 Invitations Controller create groups permission (EUVD-2026-48247)
A vulnerability marked as problematic has been reported in Getgrav Grav Plugin up to 1.0.9. The affected element is the function InvitationsController::create of the component Invitations Controller. Performing a manipulation of the argument groups results in permission issues.
This vulnerability is known as CVE-2026-65897. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invited accounts to groups that gr
ghsa_unreviewed·2026-07-23
CVE-2026-65897 [HIGH] CWE-269 Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invited accounts to groups that gr
Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invited accounts to groups that grant api.super permissions. Attackers can create invitation records with elevated group membership, and when accepted, the new account gains full super-admin API access without the inviter holding those permissions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/getgrav/grav-plugin-api/commit/f9438d4e71389b1041ac60b69b0b5714ecfa3bddhttps://github.com/getgrav/grav/commit/345e79e3abf8c15f80e612a09f6643300071324bhttps://github.com/getgrav/grav/security/advisories/GHSA-m86m-jjcg-gcvvhttps://www.vulncheck.com/advisories/grav-api-plugin-privilege-escalation-via-invitations-groupshttps://github.com/getgrav/grav/security/advisories/GHSA-m86m-jjcg-gcvv
2026-07-23
Published