Summary
CVE-2026-58656 is a high-severity vulnerability in the Grav CMS API plugin (getgrav/grav-plugin-api) affecting all versions before v1.0.0-rc.16, carrying a CVSS 4.0 score of 8.7 (High). The flaw combines two compounding weaknesses — the plugin exposes JWT authentication tokens via the ?token= URL query parameter, leaking credentials into server access logs, browser history, and HTTP Referrer headers; and every API response includes a wildcard Access-Control-Allow-Origin: * header, permitting any website to read authenticated API responses from a browser context. An attacker who obtains a leaked JWT token through any of these side channels can make fully authenticated cross-origin API calls, create persistent backdoor super-admin accounts, and exfiltrate sensitive configuration and user data from the affected Grav installation.
Technical details
- Root cause (1) — CWE-598: The
JwtAuthenticator::extractBearerToken()method accepts JWT authentication tokens via the?token=URL query parameter across all API endpoints. This causes tokens to appear in web server and CDN access logs, upstream proxy logs, browser history, and HTTP Referrer headers forwarded to third-party sites during normal navigation. - Root cause (2) — CWE-942: Every API response is served with the header
Access-Control-Allow-Origin: *. Because the token is delivered as a URL parameter rather than a credential-bearing HTTP header, the browser’s CORS credential-blocking protections do not apply, allowing JavaScript on any origin to read the full authenticated API response. - Attack chain: An attacker obtains a leaked JWT token from one of the above side channels, then crafts a malicious webpage embedding a
fetch()request to the target Grav API with the token in the URL. The browser executes the cross-origin request and reads the response, enabling arbitrary authenticated API operations without any interaction from a logged-in user. - Impact: Creation of persistent backdoor super-admin accounts; exfiltration of admin profiles, system configuration data, and user data; arbitrary content deletion. Backdoor accounts persist independently of subsequent JWT token rotation.
Affected software
- getgrav/grav-plugin-api — all versions prior to v1.0.0-rc.16
Severity
- CVSS 4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N - CVSS 3.1: 7.5 (High) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Upgrade the Grav API plugin to v1.0.0-rc.16 or later. The patch removes query-parameter token extraction and replaces the wildcard CORS policy with explicit domain allowlisting, enforcing token delivery exclusively via the
AuthorizationorX-API-TokenHTTP headers. - Post-upgrade: Audit all web server, proxy, and CDN access logs for JWT tokens exposed in URL query strings; rotate all existing JWT tokens; review Grav user accounts for any unauthorized super-admin accounts.
- If immediate patching is not feasible: Restrict network-level access to the Grav API endpoints (e.g., via firewall rules or web server ACLs) to explicitly trusted IP ranges only, to limit the pool of potential token recipients.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

