CVE-2026-72822 is a critical authorization flaw in the getgrav/grav-plugin-api package before version 1.0.13. The vulnerability affects the disable2fa endpoint, which fails to enforce API key scope caps when handling non-self administrative actions. In the vulnerable logic, the endpoint authorizes access using ACL reads such as super-admin or permission checks, but does not invoke the stronger permission-enforcement path that applies api_key_scopes restrictions. This creates an inconsistency with related functionality and allows callers to reach a critical account-security operation without the intended scope validation. As a result, an attacker holding a narrowly scoped API key associated with a super account, or a non-super account granted api.users.write, can remotely disable two-factor authentication for arbitrary non-super target accounts without supplying a valid TOTP code. The flaw weakens account protection controls and can be used as a precursor to account takeover.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication/authorization flaw in getgrav/grav-plugin-api before 1.0.13 that allows disabling 2FA on non-super target accounts via the disable2fa endpoint without enforcing API key scope caps, enabling account takeover.
A critical authorization flaw in Grav API plugin enabling attackers to disable or rotate 2FA on super-admin accounts.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.