Authentication Bypass in Grav API Plugin Affects User Management
CVE-2026-86193
8.7HIGH
What is CVE-2026-86193?
The Grav API Plugin versions before 1.0.20 exhibit a serious vulnerability where the plugin fails to properly validate group-inherited super permissions. This oversight allows non-super user managers to manipulate super-admin accounts. By exploiting the insufficient validation mechanisms, attackers with api.access and api.users.write permissions can alter password fields for group-super accounts, potentially resulting in unauthorized administrative access.
Affected Version(s)
grav-plugin-api 0 < 1.0.20
grav-plugin-api 1.0.20
