CVE-2026-56710
published 2026-08-25CVE-2026-56710: Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with…
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.28%
20.8th percentile
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on admin.super accounts, removing brute-force protection from the highest-privilege accounts without requiring equivalent permissions.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| getgrav | grav | < 1.0.16 | 1.0.16 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Getgrav Login Plugin up to 1.0.15 Unlock onApiUserListRowAction permission
vuldb·2026-08-25
CVE-2026-56710 [CRITICAL] Getgrav Login Plugin up to 1.0.15 Unlock onApiUserListRowAction permission
A vulnerability identified as critical has been detected in Getgrav Login Plugin up to 1.0.15. This issue affects the function onApiUserListRowAction of the component Unlock Handler. Performing a manipulation results in permission issues.
This vulnerability was named CVE-2026-56710. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
GHSA
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler.
ghsa_unreviewed·2026-08-25
CVE-2026-56710 [CRITICAL] CWE-863 Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler.
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on admin.super accounts, removing brute-force protection from the highest-privilege accounts without requiring equivalent permissions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-25
Published