PT-2026-86421 · Grav · Grav-Plugin-Api

·

CVE-2026-86196

·

Published

2026-09-05

·

Updated

2026-09-05

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grav API plugin versions prior to 1.0.20
Description Unauthenticated attackers can redirect password reset tokens to domains under their control by manipulating the Host header in the 'forgot-password' endpoint. By sending reset requests for any account using a malicious header, an attacker can intercept the reset token from the victim's email and achieve full account takeover, including super-admin accounts.
Recommendations Update Grav API plugin to version 1.0.20 or later.

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86196

Affected Products

Grav-Plugin-Api