CVE-2026-72830
CRITICAL
NVD
CVSS Score
9.8
Severity
CRITICAL
Published
Aug 14, 2026
Vendor
unknown
Description
Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with a scoped api.config.write key can inject arbitrary commands into scheduler.custom_jobs that execute via Symfony Process for remote code execution.