CRITICAL 9.3 NVD
CVE-2026-56710
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with ap
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on admin.super accounts, removing brute-force protection from the highest-privilege accounts without requiring equivalent permissions.
References
- https://github.com/getgrav/grav/security/advisories/GHSA-985r-mpj8-5rqw
- https://www.vulncheck.com/advisories/grav-login-plugin-before-privilege-escalation-via-unl
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-25 via NVD.
Risk Timeline
CVE Disclosed2026-08-25 · -1 days ago
Remediation Resources
vulnfeed aggregates 11266 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.