CVE-2026-86193

HIGH CVSS 4.0: 8.7 EPSS 0.21%
Updated Sep 08, 2026
Getgrav
Parameter Value
CVSS 8.7 (HIGH)
Affected Versions before 1.0.20
Fixed In 1.0.20
Type CWE-863 (Incorrect Authorization)
Vendor Getgrav
Public PoC No

grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch password fields on group-super accounts to gain full administrative control.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Getgrav Grav
cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*
1.0.20