{"id":"CVE-2026-65895","summary":"Grav API Plugin before 1.0.10 Broken Access Control","details":"Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable credential brute-forcing attacks and reconfigure CORS policies to include attacker-controlled origins with credentials enabled.","aliases":["GHSA-4pqv-2qj5-38fp"],"modified":"2026-08-30T03:46:57.666581117Z","published":"2026-07-23T11:42:16.163Z","database_specific":{"cwe_ids":["CWE-862"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65895.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65895.json"},{"type":"ADVISORY","url":"https://github.com/getgrav/grav/security/advisories/GHSA-4pqv-2qj5-38fp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65895"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/grav-api-plugin-before-broken-access-control"},{"type":"FIX","url":"https://github.com/getgrav/grav-plugin-api/commit/f9438d4e71389b1041ac60b69b0b5714ecfa3bdd"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/getgrav/grav-plugin-api","events":[{"introduced":"0"},{"fixed":"a6bc9cecf1eb0055a0d0646b614f2329765183d7"},{"fixed":"f9438d4e71389b1041ac60b69b0b5714ecfa3bdd"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.0.10"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["1.0.9","1.0.8","1.0.7","1.0.6","1.0.5","1.0.4","1.0.3","1.0.2","1.0.1","1.0.0","1.0.0-rc.16","1.0.0-rc.15","1.0.0-rc.14","1.0.0-rc.13","1.0.0-rc.12","1.0.0-rc.11","1.0.0-rc.10","1.0.0-rc.9","1.0.0-rc.8","1.0.0-rc.7","1.0.0-rc.6","1.0.0-rc.5","1.0.0-rc.4","1.0.0-rc.3","1.0.0-rc.2","1.0.0-rc.1","1.0.0-beta.17","1.0.0-beta.16","1.0.0-beta.15","1.0.0-beta.14","1.0.0-beta.13","1.0.0-beta.12","1.0.0-beta.11","1.0.0-beta.10","1.0.0-beta.9","1.0.0-beta.8","1.0.0-beta.7","1.0.0-beta.6","1.0.0-beta.5","1.0.0-beta.4","1.0.0-beta.3","1.0.0-beta.2","1.0.0-beta.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-65895.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}