CVE-2026-86196: Getgrav Grav-Plugin-API

High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can send password reset requests for any account with a malicious Host header, intercept the reset token from victim emails, and complete account takeover including super-admin accounts.

Affected products

  • Getgrav Grav-Plugin-API: before 1.0.20 (fixed in 1.0.20)

Published 2026-09-05. Last modified 2026-09-08.