CVE-2026-56710: Incorrect Authorization in getgrav grav
Description
Grav Login plugin versions before 1.0.16 contain an authorization flaw in the onApiUserListRowAction unlock handler. This flaw allows an attacker with api.users.write permission to reset login lockout counters on admin.super accounts, effectively removing brute-force protection from these high-privilege accounts without needing equivalent permissions.
CVSS v4.0
Score 9.3critical
Affected software
getgrav
grav
pkg:github/getgrav/grav-login-pluginRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-56710 describes an incorrect authorization vulnerability in the Grav Login plugin prior to version 1.0.16. The vulnerability exists because the plugin fails to validate the privilege level of the target account when handling the unlock action via the API. An attacker who has api.users.write permission can exploit this to clear lockout counters on admin.super accounts, bypassing brute-force protections on the highest privilege accounts.
Potential Impact
The vulnerability allows attackers with api.users.write permission to disable brute-force protection on admin.super accounts by clearing their login lockout counters. This increases the risk of successful brute-force attacks against these critical accounts, potentially leading to unauthorized administrative access.
Mitigation Recommendations
No official patch or remediation level is currently confirmed. Users should upgrade to Grav Login plugin version 1.0.16 or later once available. Until then, restrict api.users.write permissions to trusted users only to reduce risk. Monitor vendor advisories for updates on official fixes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-06-22T18:48:27.060Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8cf57aacd9273b49842875
Added to database: 08/25/2026, 01:52:58 UTC
Last enriched: 09/10/2026, 07:52:33 UTC
Last updated: 10/07/2026, 18:48:21 UTC
Views: 67
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.