Authentication Bypass in Grav API Plugin Affects User Management
CVE-2026-86193

8.7HIGH

Key Information:

Vendor

Getgrav

Vendor
CVE Published:
5 September 2026

What is CVE-2026-86193?

The Grav API Plugin versions before 1.0.20 exhibit a serious vulnerability where the plugin fails to properly validate group-inherited super permissions. This oversight allows non-super user managers to manipulate super-admin accounts. By exploiting the insufficient validation mechanisms, attackers with api.access and api.users.write permissions can alter password fields for group-super accounts, potentially resulting in unauthorized administrative access.

Affected Version(s)

grav-plugin-api 0 < 1.0.20

grav-plugin-api 1.0.20

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

1K0CT
.