CVE-2026-57852
Received Received - Intake

Authentication Bypass in Grav CMS Scheduler-Webhook Plugin

Vulnerability report for CVE-2026-57852, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-20

Last updated on: 2026-07-20

Assigner: VulnCheck

Description

Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured scheduled jobs by exploiting a short-circuit logic flaw in the webhook token validation. Attackers can send a single unauthenticated POST request to the scheduler webhook endpoint to execute all configured scheduled jobs or target a specific job, causing unintended execution of operator-defined commands under the web server process user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-20
Last Modified
2026-07-20
Generated
2026-07-21
AI Q&A
2026-07-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
grav cms_scheduler_webhook_plugin *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-303 The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Grav CMS scheduler-webhook plugin has an authentication bypass flaw. Unauthenticated attackers can send a single POST request to the scheduler webhook endpoint to trigger scheduled jobs without proper validation. This allows execution of operator-defined commands under the web server process user.

Detection Guidance

Check Grav CMS scheduler-webhook plugin logs for unauthenticated POST requests to the webhook endpoint. Monitor for unexpected job executions or commands run under the web server process user. Inspect network traffic for suspicious POST requests to paths like /scheduler/webhook or similar configured endpoints.

Impact Analysis

Attackers could execute unauthorized commands on your server, potentially leading to data theft, system compromise, or disruption of scheduled tasks. This could affect website integrity, data confidentiality, and operational stability.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's integrity and confidentiality requirements or HIPAA's safeguards for protected health information. Non-compliance risks include fines and legal penalties.

Mitigation Strategies

Disable the scheduler-webhook plugin immediately if not in use. Update Grav CMS and the plugin to the latest patched version. Restrict access to the webhook endpoint via firewall rules or server configuration. Review and audit all scheduled jobs for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57852. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart