Authorization bypass through user-controlled key in Grav CMS - CVE-2025-66306

 

Authorization bypass through user-controlled key in Grav CMS - CVE-2025-66306

Published: May 5, 2026


Vulnerability identifier: #VU130057
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-66306
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the /admin/accounts/users/{username} endpoint when handling requests for another user's account details. A remote user can send a request for another user's account page to disclose sensitive information.

Sensitive data may still be present in the response source even when the application returns an HTTP 403 response.


Affected software

Grav CMS

How to mitigate CVE-2025-66306

Install security update from vendor's website.

Grav CMS - update to 1.8.0 beta.27

External References

Related Security Bulletins