Grav Login plugin — CVE-2026-56710 (Critical)

Date Aug 25, 2026
Type Vendor advisory
Signal Critical vendor advisory
Vendor / Product Grav · Login plugin
CVE CVE-2026-56710
Critical vendor advisory CVE-2026-56710

Summary

Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on admin.super accounts, removing brute-force protection from the highest-privilege accounts without requiring equivalent permissions.

Why it matters

This CVE carries a CRITICAL severity rating (CVSS 9.8) in Grav Login plugin. Patch or mitigate promptly.

Operator check

Review CVE-2026-56710 in your asset inventory. Apply patches per vendor guidance and verify Login plugin is not exposed. CVSS score: 9.8.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.