CVE-2026-56710Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on admin.super accounts, removing brute-force protection from the highest-privilege accounts without requiring equivalent permissions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-25: 2Patch / Workaround · 2026-08-25: 2Technical Details · 2026-08-25: 208-25
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical vulnerability in #Grav CMS Login. CVE-2026-56710 CVSS: 9.3. An attacker can clear login lockout counters from admin accounts, allowing brute-force attacks. More info: https://github.com/getgrav/grav/security/advisories/GHSA-985r-mpj8-5rqw #Patch #Patch #Patch

    Post summary

    An exceptionally high‑severity CVE‑2026‑56710 for Grav CMS was disclosed, detailing how attackers can reset login lockout counters to facilitate brute‑force attacks, and the post references a vendor security advisory that presumably includes a patch (see the provided GitHub link).

    01001334
    7.2K followersView on X
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-56710 (CVSS 9.8) affects Grav Login plugin versions before 1.0.16. Update immediately if your environment uses this plugin. via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/erPPyCuSeS

    Post summary

    The tweet announces a high‑severity CVE affecting Grav Login plugin versions before 1.0.16 and urges users to update immediately, highlighting the availability of a patch or mitigation.

    0000040
    93 followersView on X

Explore more