← Back to overview

CVE-2026-56710 affects Grav Login plugin versions before 1.0.16, where the onApiUserListRowAction unlock handler fails to validate the privilege level of the target account. An attacker holding api.users.write permission can exploit this flaw to clear login lockout counters on admin.super accounts. This effectively strips brute-force protection from the highest-privilege accounts in a Grav CMS installation without requiring equivalent super-admin permissions. The vulnerability represents a privilege escalation/authorization bypass issue that could facilitate subsequent credential-based attacks against administrator accounts. It has been assigned a high criticality rating. Fixes are available in version 1.0.16 of the Grav Login plugin, and advisories have been published on GitHub and VulnCheck.

Affected products

  • Grav CMS
  • Grav Login Plugin

Related CVE's

  • CVE-2026-56710

Categories

  • Identity & Access
  • Web Technologies