Vulnerability Description
Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can send password reset requests for any account with a malicious Host header, intercept the reset token from victim emails, and complete account takeover including super-admin accounts.
Related Weaknesses (CWE)
References
- https://github.com/getgrav/grav/security/advisories/GHSA-262p-56vv-7v5r
- https://www.vulncheck.com/advisories/grav-api-plugin-before-1.0.20-authenticatio
FAQ
What is CVE-2026-86196?
CVE-2026-86196 is a documented vulnerability. Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacke...
How severe is CVE-2026-86196?
CVSS scoring is not yet available for CVE-2026-86196. Check NVD for updates.
Is there a patch for CVE-2026-86196?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.