{"id":"CVE-2026-86193","title":"grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts","summary":"grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch passwor…","severity":"high","cvss":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-863"],"vendor":"getgrav","product":"grav-plugin-api","affected":["grav-plugin-api < 1.0.20"],"published":"2026-09-05","updated":"2026-09-08","sourceUpdated":"2026-09-08T20:05:53.177","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86193","references":[{"url":"https://github.com/getgrav/grav/security/advisories/GHSA-vv8m-jqpm-38x4","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/grav-api-plugin-authentication-bypass-via-group-inherited-super","label":"disclosure@vulncheck.com"},{"url":"https://github.com/getgrav/grav/security/advisories/GHSA-vv8m-jqpm-38x4","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"epss":0.00215,"epssPercentile":0.12195,"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2026-09-08T13:16:12.939796Z"},"cvssSource":"cna","ingestedAt":"2026-09-06T08:52:35.034Z","slug":"CVE-2026-86193","body":"## Overview\n\ngrav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch password fields on group-super accounts to gain full administrative control.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":60,"depthScoreParts":{"impact":47.8,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":5514,"id":"CVE-2026-86193","ts":1788887297212,"field":"exploit_available","old":"false","new":"true"},{"seq":5513,"id":"CVE-2026-86193","ts":1788887297212,"field":"cvss","old":null,"new":"8.7"},{"seq":5512,"id":"CVE-2026-86193","ts":1788887297212,"field":"severity","old":"none","new":"high"},{"seq":4390,"id":"CVE-2026-86193","ts":1788886404490,"field":"exploit_available","old":"true","new":"false"},{"seq":4389,"id":"CVE-2026-86193","ts":1788886404490,"field":"cvss","old":"8.7","new":null},{"seq":4388,"id":"CVE-2026-86193","ts":1788886404490,"field":"severity","old":"high","new":"none"},{"seq":3103,"id":"CVE-2026-86193","ts":1788883068382,"field":"exploit_available","old":"false","new":"true"},{"seq":3102,"id":"CVE-2026-86193","ts":1788883068382,"field":"cvss","old":null,"new":"8.7"},{"seq":3101,"id":"CVE-2026-86193","ts":1788883068382,"field":"severity","old":"none","new":"high"},{"seq":2132,"id":"CVE-2026-86193","ts":1788882472364,"field":"exploit_available","old":"true","new":"false"},{"seq":2131,"id":"CVE-2026-86193","ts":1788882472364,"field":"cvss","old":"8.7","new":null},{"seq":2130,"id":"CVE-2026-86193","ts":1788882472364,"field":"severity","old":"high","new":"none"},{"seq":279,"id":"CVE-2026-86193","ts":1788881646101,"field":"exploit_available","old":"false","new":"true"},{"seq":278,"id":"CVE-2026-86193","ts":1788881646101,"field":"cvss","old":null,"new":"8.7"},{"seq":277,"id":"CVE-2026-86193","ts":1788881646101,"field":"severity","old":"none","new":"high"}]}