CVE-2026-57852

Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured scheduled jobs by exploiting a short-circuit logic flaw in the webhook token validation. Attackers can send a single unauthenticated POST request to the scheduler webhook endpoint to execute all configured scheduled jobs or target a specific job, causing unintended execution of operator-defined commands under the web server process user.
Configurations

No configuration.

History

20 Jul 2026, 22:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-20 22:17

Updated : 2026-07-21 18:57


NVD link : CVE-2026-57852

Mitre link : CVE-2026-57852

CVE.ORG link : CVE-2026-57852


JSON object : View

Products Affected

No product.

CWE
CWE-303

Incorrect Implementation of Authentication Algorithm