← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 5, 2026 · 13:18via CVEFeed

CVE-2026-86193 - Grav API Plugin Authentication Bypass via Group-Inherited Super

Brief

CVE ID : CVE-2026-86193

Published : Sept. 5, 2026, 1:18 p. m.

  • 7 hours, 27 minutes ago

Description : grav-plugin-api before 1.

  • 20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api. access and api. users. write can patch password fields on group-super accounts to gain full administrative control.

Severity: 8.7

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed