Executive brief
The Grav Login plugin, which manages user authentication and profiles for the Grav CMS, contains a security flaw that allows standard users to grant themselves administrative rights. By submitting a specially crafted profile update request, a logged-in user can bypass security restrictions to become a 'super-admin.' This level of access allows an attacker to take full control of the website, modify sensitive data, and potentially execute malicious code on the underlying server.
Technical details
A privilege escalation vulnerability exists in the 'processUserProfile()' handler (the 'update_user' task) of the Grav Login plugin. The handler fails to strip sensitive privilege fields such as 'groups' and 'access' from user-submitted form data before persisting it to the account YAML file. This occurs when the default 'regular'/DataUser account backend is used and an administrator has configured 'groups' or 'access' as allowed registration fields. An authenticated attacker can POST crafted data (e.g., 'access[admin][super]=true') to their own profile to gain super-admin privileges. This access can be further leveraged for Remote Code Execution (RCE) via the Grav scheduler or Twig evaluation. The issue is fixed in version 3.8.12.
Affected products
- Grav Login Plugin (grav-plugin-login) <= 3.8.11
Timeline
- 2026-07-08: advisory: Vendor advisory published on GitHub
- 2026-07-22: disclosed: CVE published to NVD
- 2026-07-22: patched: Fixed in version 3.8.12