CVE-2026-80204
grav5/100
exploitation likelihood
CVSS9.3
EPSS—
KEVNone
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18 does not apply the API-key scope cap in the injectSecurityTab() function of BlueprintController when deciding whether a page's security/permissions blueprint section is editable. Because the function performs raw isSuperAdmin()/hasPermission() checks without a request parameter, it cannot enforce scopeAllows(). A caller holding a scoped API key may therefore see (and potentially edit) page permission fields beyond the scope granted to t
No EPSS/KEV signal · CVSS base 9.3
Public PoC / Exploit
No public PoC/exploit references indexed yet (Exploit-DB / nuclei). Newly-disclosed CVEs often have none — exploit publication lags disclosure.
References2