Privilege Escalation Vulnerability in Grav Plugin API by Grav
CVE-2026-86195
8.7HIGH
What is CVE-2026-86195?
The Grav Plugin API prior to version 1.0.20 is susceptible to a privilege escalation vulnerability due to insufficient validation in the InvitationsController. The stripSuperFlags() method fails to effectively remove certain dot-keyed super flags, allowing a non-super user with specific permissions to create invitations containing these flags. This exploit enables attackers to bypass access controls and establish unauthorized super-admin accounts, granting them full access to the site with a valid JWT token. Immediate updates are necessary to mitigate this critical security risk.
Affected Version(s)
grav-plugin-api 0 < 1.0.20
grav-plugin-api 1.0.20
