


Perceptive Security
SOC/SIEM Consultancy

Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with ap…
Published:
25 August 2026 at 00:00:00
Alert date:
25 August 2026 at 05:06:46
Source:
nvd.nist.gov
Web Technologies, Identity & Access
CVE-2026-56710 affects Grav Login plugin versions before 1.0.16, where the onApiUserListRowAction unlock handler fails to validate the privilege level of the target account. An attacker holding api.users.write permission can exploit this flaw to clear login lockout counters on admin.super accounts. This effectively strips brute-force protection from the highest-privilege accounts in a Grav CMS installation without requiring equivalent super-admin permissions. The vulnerability represents a privilege escalation/authorization bypass issue that could facilitate subsequent credential-based attacks against administrator accounts. It has been assigned a high criticality rating. Fixes are available in version 1.0.16 of the Grav Login plugin, and advisories have been published on GitHub and VulnCheck.
Technical details
Mitigation steps:
Affected products:
Grav Login Plugin
Grav CMS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-56710
https://github.com/getgrav/grav/security/advisories/GHSA-985r-mpj8-5rqw
https://www.vulncheck.com/advisories/grav-login-plugin-before-privilege-escalation-via-unlock
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
