top of page
perceptive_background_267k.jpg

Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with ap…

Published:

25 August 2026 at 00:00:00

Alert date:

25 August 2026 at 05:06:46

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

CVE-2026-56710 affects Grav Login plugin versions before 1.0.16, where the onApiUserListRowAction unlock handler fails to validate the privilege level of the target account. An attacker holding api.users.write permission can exploit this flaw to clear login lockout counters on admin.super accounts. This effectively strips brute-force protection from the highest-privilege accounts in a Grav CMS installation without requiring equivalent super-admin permissions. The vulnerability represents a privilege escalation/authorization bypass issue that could facilitate subsequent credential-based attacks against administrator accounts. It has been assigned a high criticality rating. Fixes are available in version 1.0.16 of the Grav Login plugin, and advisories have been published on GitHub and VulnCheck.

Technical details

Mitigation steps:

Affected products:

Grav Login Plugin
Grav CMS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page