Description
grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch password fields on group-super accounts to gain full administrative control.
Published: 2026-09-05
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Grav API Plugin before version 1.0.20 allows a non‑super user manager to bypass permission validation on accounts that inherit super rights through a group. An attacker who has api.access and api.users.write permissions can patch the password field of any group‑super account, effectively taking full administrative control of the site. This weakness leads to a loss of confidentiality, integrity, and availability of the administrative functions of Grav, as unauthorized users can assume a super‑admin identity.

Affected Systems

The vulnerability affects the Grav API Plugin distributed by Getgrav, specifically versions prior to 1.0.20. Systems running the vulnerable plugin combination are at risk.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity of the flaw. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is through the API: an attacker must possess api.access and api.users.write scopes. Once these scopes are obtained, the exploit is trivial, as no additional authentication or privilege escalation steps are required beyond the legitimate API permissions.

Generated by OpenCVE AI on September 5, 2026 at 13:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Grav API Plugin update to version 1.0.20 or newer, which corrects the group‑inherited super permission validation.
  • Limit the api.access and api.users.write permissions so that only true super‑admin accounts have them, removing these scopes from non‑super managers.
  • Review all group assignments to ensure no non‑super users inadvertently inherit super rights, and remove or correct any such group memberships.

Generated by OpenCVE AI on September 5, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch password fields on group-super accounts to gain full administrative control.
Title Grav API Plugin Authentication Bypass via Group-Inherited Super
First Time appeared Getgrav
Getgrav grav
Weaknesses CWE-863
CPEs cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*
Vendors & Products Getgrav
Getgrav grav
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-05T12:09:07.441Z

Reserved: 2026-09-05T11:51:31.102Z

Link: CVE-2026-86193

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-05T13:18:14.593

Modified: 2026-09-05T13:18:14.593

Link: CVE-2026-86193

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T13:30:05Z

Weaknesses