


Perceptive Security
SOC/SIEM Consultancy

Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Control-Allow-Origin: *, allowing unauthenti…
Published:
7 juli 2026 om 22:00:00
Alert date:
8 juli 2026 om 16:06:44
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Data Breach & Exfiltration
The Grav API plugin before v1.0.0-rc.16 contains a critical vulnerability where JWT tokens are accepted via the ?token= URL query parameter while the API responds with Access-Control-Allow-Origin: *, creating a dangerous CORS misconfiguration. This combination allows unauthenticated attackers to perform fully authenticated cross-origin API requests from any malicious website. JWT tokens can be harvested from access logs, proxy logs, browser history, or HTTP Referrer headers due to their exposure in URL query strings. Successful exploitation enables attackers to create persistent backdoor super-admin accounts, effectively achieving full administrative takeover of the Grav CMS instance. Sensitive configuration data and user data can also be exfiltrated. The vulnerability is particularly severe because it combines token leakage via URLs with a wildcard CORS policy, making exploitation straightforward. Users should upgrade to v1.0.0-rc.16 or later immediately.
Technical details
Mitigation steps:
Affected products:
Grav API plugin
Grav CMS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-58656
https://github.com/getgrav/grav/security/advisories/GHSA-hqm9-5xxw-4qxp
https://www.vulncheck.com/advisories/grav-api-plugin-cross-origin-admin-account-takeover-via-cors-wildcard-and-jwt-query-parameter
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
