Junglewise Threat Intelligence

CVE-2026-65603: Grav Login Plugin privilege escalation in profile update handler

CVE-2026-65603 · Severity: high · CVSS 8.8 · Published 2026-07-22

Vendors: Grav.

Executive brief

The Grav Login plugin, which manages user authentication and profiles for the Grav CMS, contains a security flaw that allows standard users to grant themselves administrative rights. By submitting a specially crafted profile update request, a logged-in user can bypass security restrictions to become a 'super-admin.' This level of access allows an attacker to take full control of the website, modify sensitive data, and potentially execute malicious code on the underlying server.

Technical details

A privilege escalation vulnerability exists in the 'processUserProfile()' handler (the 'update_user' task) of the Grav Login plugin. The handler fails to strip sensitive privilege fields such as 'groups' and 'access' from user-submitted form data before persisting it to the account YAML file. This occurs when the default 'regular'/DataUser account backend is used and an administrator has configured 'groups' or 'access' as allowed registration fields. An authenticated attacker can POST crafted data (e.g., 'access[admin][super]=true') to their own profile to gain super-admin privileges. This access can be further leveraged for Remote Code Execution (RCE) via the Grav scheduler or Twig evaluation. The issue is fixed in version 3.8.12.

Affected products

  • Grav Login Plugin (grav-plugin-login) <= 3.8.11

Timeline

  • 2026-07-08: advisory: Vendor advisory published on GitHub
  • 2026-07-22: disclosed: CVE published to NVD
  • 2026-07-22: patched: Fixed in version 3.8.12

References

Related threats