CVE-2026-86196 Details
Description
Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can send password reset requests for any account with a malicious Host header, intercept the reset token from victim emails, and complete account takeover including super-admin accounts.
A vulnerability exists in the Grav API plugin in versions prior to 1.0.20, where the password reset links are generated based on the untrusted Host header in the forgot-password endpoint. This flaw allows unauthenticated attackers to redirect reset tokens to domains they control. Attackers can exploit this by sending password reset requests for any account, using a malicious Host header to intercept the reset token from the victim's email. Once obtained, the attacker can use the token to take over the victim's account, including super-admin accounts.
Users can upgrade to Grav API plugin version 1.0.20 or later, where this vulnerability has been fixed. For those unable to upgrade, setting the Custom Base URL in Grav's system configuration to the site's full address, including the scheme, can mitigate the issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 5, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/getgrav/grav/security/advisories/GHSA-262p-56vv-7v5r | [email protected] | AdvisoryExploitRemedyVendor |
| https://www.vulncheck.com/advisories/grav-api-plugin-before-1.0.20-authentication-bypass-via-host-header | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Grav API plugin | <= 1.0.19 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 5, 2026 | New CVE Received | [email protected] |
Volerion