CRITICAL
9.8 CVE-2026-56710 Published 25 Aug 2026
Grav Login Plugin Privilege Escalation
Worried this affects one of your servers?
Grav Login plugin versions before 1.0.16 have a vulnerability in the onApiUserListRowAction unlock handler. This allows an attacker with api.users.write permission to clear login lockout counters on admin.super accounts.
This removes brute-force protection from the highest-privilege accounts, potentially leading to unauthorized access.
Reference: CVE-2026-56710 on NVD
← Back to Security News