CVE-2026-86196
Grav API Plugin before 1.0.20 Authentication Bypass via Host Header
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can send password reset requests for any account with a malicious Host header, intercept the reset token from victim emails, and complete account takeover including super-admin accounts.
| CWE | CWE-290 |
| Vendor | getgrav |
| Product | grav-plugin-api |
| Published | Sep 5, 2026 |
| Last Updated | Sep 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for getgrav grav-plugin-api
Be the first to know when new unknown vulnerabilities affecting getgrav grav-plugin-api are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
getgrav / grav-plugin-api
0 < 1.0.20
References
Credits
๐ 1K0CT