Grav Login plugin — CVE-2026-56710 (Critical)
Critical vendor advisory
CVE-2026-56710
Summary
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on admin.super accounts, removing brute-force protection from the highest-privilege accounts without requiring equivalent permissions.
Why it matters
This CVE carries a CRITICAL severity rating (CVSS 9.8) in Grav Login plugin. Patch or mitigate promptly.
Operator check
Review CVE-2026-56710 in your asset inventory. Apply patches per vendor guidance and verify Login plugin is not exposed. CVSS score: 9.8.
Sources
PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.