Authentication Bypass in Grav API Plugin by GetGrav
CVE-2026-86196

8.7HIGH

Key Information:

Vendor

Getgrav

Vendor
CVE Published:
5 September 2026

What is CVE-2026-86196?

The Grav API plugin prior to version 1.0.20 contains a vulnerability that allows attackers to exploit untrusted Host headers in the forgot-password endpoint. This flaw may enable unauthorized individuals to generate password reset links directed to malicious sites, leading to potential interception of reset tokens sent to users. Consequently, attackers could gain access to user accounts, including those with administrative privileges, posing a significant security threat to users of the Grav API.

Affected Version(s)

grav-plugin-api 0 < 1.0.20

grav-plugin-api 1.0.20

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

1K0CT
.