Vulnerability Description
grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch password fields on group-super accounts to gain full administrative control.
Related Weaknesses (CWE)
References
- https://github.com/getgrav/grav/security/advisories/GHSA-vv8m-jqpm-38x4
- https://www.vulncheck.com/advisories/grav-api-plugin-authentication-bypass-via-g
- https://github.com/getgrav/grav/security/advisories/GHSA-vv8m-jqpm-38x4
FAQ
What is CVE-2026-86193?
CVE-2026-86193 is a documented vulnerability. grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access ...
How severe is CVE-2026-86193?
CVSS scoring is not yet available for CVE-2026-86193. Check NVD for updates.
Is there a patch for CVE-2026-86193?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.