| Summary | Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upload to write an arbitrary YAML file into user/accounts/, then log in as the newly created account with api.super privileges. This results in full administrative compromise of the Grav API. This vulnerability is fixed in API 1.0.0-beta.17. |
|---|---|
| Publication Date | May 13, 2026, 7:16 a.m. |
| Registration Date | May 15, 2026, 4:18 a.m. |
| Last Update | May 14, 2026, 1:16 a.m. |