Privilege Escalation in Grav Login Plugin by Grav
CVE-2026-56710
9.3CRITICAL
What is CVE-2026-56710?
The Grav Login plugin versions prior to 1.0.16 contain a security flaw where the privilege level of the target account is not validated in the unlock handler of the onApiUserListRowAction. This allows an attacker with the api.users.write permission to manipulate login lockout counters for admin.super accounts. Consequently, they can disable brute-force protection mechanisms aimed at the highest-privilege accounts, significantly increasing the risk of unauthorized access and account compromise.
Affected Version(s)
grav 0 < 1.0.16
grav 1.0.16
