Privilege Escalation in Grav Login Plugin by Grav
CVE-2026-56710

9.3CRITICAL

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-56710?

The Grav Login plugin versions prior to 1.0.16 contain a security flaw where the privilege level of the target account is not validated in the unlock handler of the onApiUserListRowAction. This allows an attacker with the api.users.write permission to manipulate login lockout counters for admin.super accounts. Consequently, they can disable brute-force protection mechanisms aimed at the highest-privilege accounts, significantly increasing the risk of unauthorized access and account compromise.

Affected Version(s)

grav 0 < 1.0.16

grav 1.0.16

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

alham-rizvi
.