PT-2026-81137 · Grav · Grav Login

·

CVE-2026-56710

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grav Login plugin versions prior to 1.0.16
Description Insufficient validation of the target account privilege level occurs in the onApiUserListRowAction unlock handler. An attacker possessing api.users.write permission can clear login lockout counters on admin.super accounts. This action removes brute-force protection from the highest-privilege accounts without the attacker needing equivalent administrative permissions.
Recommendations Update Grav Login plugin to version 1.0.16 or later.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56710

Affected Products

Grav Login