PatchSiren cyber security CVE debrief
CVE-2026-56710 getgrav CVE debrief
The Grav Login plugin, versions before 1.0.16, contains a critical vulnerability (CVE-2026-56710) that allows attackers with api.users.write permission to clear login lockout counters on admin.super accounts. This effectively removes brute-force protection from high-privilege accounts. Administrators and users of Grav Login plugin, especially those with high-privilege accounts, should be aware of this vulnerability and take necessary actions to update and secure their systems. The CVE record was published on 2026-08-25T02:16:43.073Z and has not been modified since then. This issue highlights the importance of validating target account privilege levels in the onApiUserListRowAction unlock handler.
- Vendor
- getgrav
- Product
- grav
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-25
- Original CVE updated
- 2026-08-31
- Advisory published
- 2026-08-25
- Advisory updated
- 2026-08-31
Who should care
Administrators and users of Grav Login plugin, especially those with high-privilege accounts, should be aware of this vulnerability and take necessary actions to update and secure their systems. This includes reviewing and updating the Grav Login plugin to version 1.0.16 or later, restricting api.users.write permission to trusted users, and monitoring login attempts and lockout counters for suspicious activity. Implementing additional security measures, such as IP blocking or rate limiting, may also be considered to enhance system security. Security teams and vulnerability management teams should prioritize this vulnerability for remediation due to its critical severity and potential impact on system security posture. Affected operators and platforms should take immediate action to protect their environments. This vulnerability may require review of compensating controls and asset inventory to ensure adequate protection. Monitoring and detection capabilities should be reviewed to ensure they can identify potential exploitation attempts. Rollback and change window processes should be evaluated to ensure timely remediation. Source tracking and verification of remediation should be performed to confirm the vulnerability is properly addressed. The CVE Program and NVD provide official guidance and details on this vulnerability, which should be consulted for further information and updates. Vulnerability management processes should be updated to reflect the severity and potential impact of this vulnerability. Security awareness and training programs may need to be updated to educate users on the risks associated with this vulnerability and the necessary mitigation steps. Incident response plans should be reviewed to ensure they are prepared to handle potential exploitation of this vulnerability. The vulnerability management team should track exceptions and retest remediated assets to confirm the vulnerability is properly addressed. The security team should close the item only after evidence is documented to confirm remediation. The CVE-2026-56710 vulnerability highlights the importance of robust security practices, including regular updates, access controls, and dilog
Technical summary
The Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on admin.super accounts, effectively removing brute-force protection from high-privilege accounts. This vulnerability allows for potential unauthorized access to sensitive areas of the system. Official sources, including the CVE Program and NVD, provide details on this vulnerability.
Defensive priority
CVE-2026-56710 is a critical vulnerability with a CVSS score of 9.3, allowing attackers with api.users.write permission to clear login lockout counters on admin.super accounts, effectively removing brute-force protection from high-privilege accounts.
Recommended defensive actions
- Review and update Grav Login plugin to version 1.0.16 or later
- Restrict api.users.write permission to trusted users
- Monitor login attempts and lockout counters for suspicious activity
- Consider implementing additional security measures, such as IP blocking or rate limiting
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE-2026-56710 record indicates that Grav Login plugin versions before 1.0.16 are vulnerable to an issue where an attacker with api.users.write permission can clear login lockout counters on admin.super accounts. Official sources, including the CVE Program and NVD, provide details on this vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-56710 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-56710
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-56710 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-56710
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/getgrav/grav/security/advisories/GHSA-985r-mpj8-5rqw
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/grav-login-plugin-before-privilege-escalation-via-unlock
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.