CVE-2026-86193: Getgrav Grav-Plugin-API

High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.

grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch password fields on group-super accounts to gain full administrative control.

Affected products

  • Getgrav Grav-Plugin-API: before 1.0.20 (fixed in 1.0.20)

Published 2026-09-05. Last modified 2026-09-08.