CVE-2026-86193

grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch password fields on group-super accounts to gain full administrative control.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-05 13:18

Updated : 2026-09-08 20:05


NVD link : CVE-2026-86193

Mitre link : CVE-2026-86193

CVE.ORG link : CVE-2026-86193


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization