CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-72822 — The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) ...

·Source: NIST NVD

Updated:

Executive Summary

The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, disable2fa authorizes the admin (non-self) path solely via ACL reads (isSuperAdmin/hasPermission) and never invokes requirePermission(), so the api_key_scopes cap is never applied. As a result, a holder of a narrow-

Analysis

The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, disable2fa authorizes the admin (non-self) path solely via ACL reads (isSuperAdmin/hasPermission) and never invokes requirePermission(), so the api_key_scopes cap is never applied. As a result, a holder of a narrow-scope API key on a super account, or a non-super account whose ACL includes api.users.write, can force-disable two-factor authentication on any non-super target account via POST /api/v1/users/{user}/2fa/disable without providing a TOTP code, facilitating account takeover. CVSS Score: 9.8. Published: 2026-08-14T12:16:45.267.

Indicators of Compromise (1)

CVE (1)
CVE-2026-72822
Source Attribution

Originally published by NIST NVD on Aug 14, 2026. Verified by: NIST.

Related Threats