Executive brief
A security flaw in the Grav Admin Panel allows users with limited account-creation permissions to overwrite existing accounts, including those of high-level administrators. By creating a new user with an existing administrator's username, an attacker can effectively strip that administrator of their access rights. This results in a lockout of legitimate administrators and a complete loss of management control over the website.
Technical details
A business logic vulnerability exists in Grav's user management module due to insecure 'Create or Update' logic. When a user with 'admin.users.create' permissions attempts to create a new user with a username that already exists, the system fails to validate the conflict and instead overwrites the existing user's configuration file (e.g., YAML metadata). While the attacker cannot grant themselves higher privileges, they can effectively wipe the permissions of a target Super User, leading to a Denial of Service (DoS) on administrative functions. The fix involves tightening the uniqueness guard in 'UserObject::save' and ensuring the check applies across all storage backends.
Affected products
- getgrav Grav < 2.0.0-beta.2
Timeline
- 2026-04-24: patched: Fix applied to Grav core 2.0 branch.
- 2026-05-05: disclosed: GitHub Advisory published.
- 2026-05-11: advisory: NVD published CVE-2026-42609.