CVE-2026-56710: Getgrav Grav
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on admin.super accounts, removing brute-force protection from the highest-privilege accounts without requiring equivalent permissions.
Affected products
- Getgrav Grav: before 1.0.16 (fixed in 1.0.16)
Published 2026-08-25. Last modified 2026-08-31.