Vulnerability Description
Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to execute form actions defined on login-restricted or unpublished pages. Attackers can POST to any public page with a restricted form's name to trigger save, upload, email, or call actions without authentication.
Related Weaknesses (CWE)
References
- https://github.com/getgrav/grav/security/advisories/GHSA-33m4-m988-5fvh
- https://www.vulncheck.com/advisories/grav-form-plugin-before-9.1.22-cross-page-f
FAQ
What is CVE-2026-86194?
CVE-2026-86194 is a documented vulnerability. Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to execute form actions defined on login-restricted or unpublis...
How severe is CVE-2026-86194?
CVSS scoring is not yet available for CVE-2026-86194. Check NVD for updates.
Is there a patch for CVE-2026-86194?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.