CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-62387

highCVSS 7.1covered by 1 sourcefirst seen 2026-07-17
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default CORS configuration on all responses, including authenticated endpoints and preflight (OPTIONS) responses. Because the plugin accepts credentials via the Authorization and X-API-Token headers (set programmatically by JavaScript rather than via cookies), an attacker who obtains a valid access token (e.g., via log leakage, Referer headers, browser history, or network capture) can issue fully authenticated cross-origin requests from any malicious website to read sensitive data and perform write operations as the token's user. Fixed in 1.0.0-rc.16.

⚡ Watch CVE-2026-62387

Get an email if CVE-2026-62387 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-62387

CVE.org record

Embed the live status

CVE-2026-62387 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-62387 status](https://www.csirts.com/badge/CVE-2026-62387)](https://www.csirts.com/cve/CVE-2026-62387)