CVE-2026-86193
Grav API Plugin Authentication Bypass via Group-Inherited Super
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch password fields on group-super accounts to gain full administrative control.
| CWE | CWE-863 |
| Vendor | getgrav |
| Product | grav-plugin-api |
| Published | Sep 5, 2026 |
| Last Updated | Sep 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for getgrav grav-plugin-api
Be the first to know when new unknown vulnerabilities affecting getgrav grav-plugin-api are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
getgrav / grav-plugin-api
0 < 1.0.20
References
Credits
๐ 1K0CT