Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-72830

CRITICAL NVD
CVSS Score 9.8
Severity CRITICAL
Published Aug 14, 2026
Vendor unknown

Description

Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with a scoped api.config.write key can inject arbitrary commands into scheduler.custom_jobs that execute via Symfony Process for remote code execution.

References