CRITICAL 9.8 CVE-2026-56710 Published 25 Aug 2026

Grav Login Plugin Privilege Escalation

Worried this affects one of your servers?

Grav Login plugin versions before 1.0.16 have a vulnerability in the onApiUserListRowAction unlock handler. This allows an attacker with api.users.write permission to clear login lockout counters on admin.super accounts.

This removes brute-force protection from the highest-privilege accounts, potentially leading to unauthorized access.

Reference: CVE-2026-56710 on NVD

← Back to Security News