NONE · 0

CVE-2026-86196

Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacke...

Vulnerability Description

Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can send password reset requests for any account with a malicious Host header, intercept the reset token from victim emails, and complete account takeover including super-admin accounts.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-86196?

CVE-2026-86196 is a documented vulnerability. Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacke...

How severe is CVE-2026-86196?

CVSS scoring is not yet available for CVE-2026-86196. Check NVD for updates.

Is there a patch for CVE-2026-86196?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.