{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/grav-login-plugin-grav-plugin-login--3.8.11/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-65603"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Grav Login plugin (grav-plugin-login) \u003c= 3.8.11"],"_cs_severities":["critical"],"_cs_tags":["privilege-escalation","web-vulnerability","grav","cms"],"_cs_type":"advisory","_cs_vendors":["Grav"],"content_html":"\u003cp\u003eThe Grav Login plugin, specifically versions up to and including 3.8.11, contains a critical privilege escalation vulnerability identified as CVE-2026-65603. This flaw allows an authenticated low-privilege user to elevate their privileges to super-admin status. The vulnerability resides in the \u003ccode\u003eprocessUserProfile()\u003c/code\u003e handler, responsible for user profile updates. If a Grav administrator has configured the \u003ccode\u003eplugins.login.user_registration.fields\u003c/code\u003e setting to include 'groups' or 'access' fields, and the default 'regular'/DataUser account backend is in use, the handler fails to sanitize these privilege-related fields from user-submitted form data. Consequently, an attacker can send a crafted POST request, for example, \u003ccode\u003eaccess[admin][super]=true\u003c/code\u003e, which the system then processes, inadvertently granting them super-admin access. This elevated access enables unauthorized control over the Grav admin panel, allowing for potential remote code execution through scheduler manipulation and Twig template evaluation, posing a significant risk to the integrity and confidentiality of the Grav instance.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker gains initial access to a Grav system with a valid, low-privilege authenticated user account.\u003c/li\u003e\n\u003cli\u003eThe attacker identifies that the Grav Login plugin (versions \u0026lt;= 3.8.11) is installed and that the administrator has configured the \u003ccode\u003eplugins.login.user_registration.fields\u003c/code\u003e to include 'groups' and/or 'access' fields.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts an HTTP POST request designed to update their user profile via the \u003ccode\u003eprocessUserProfile()\u003c/code\u003e handler.\u003c/li\u003e\n\u003cli\u003eThe crafted POST request's form data includes malicious privilege-escalation parameters, such as \u003ccode\u003eaccess[admin][super]=true\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eprocessUserProfile()\u003c/code\u003e handler processes this request but fails to strip the sensitive 'groups' or 'access' fields from the user-supplied data, unlike the registration handler.\u003c/li\u003e\n\u003cli\u003eThe system updates the attacker's user profile with the elevated privileges specified in the crafted request.\u003c/li\u003e\n\u003cli\u003eThe attacker's low-privilege account is successfully escalated to super-admin status.\u003c/li\u003e\n\u003cli\u003eWith super-admin access, the attacker can now access the Grav admin panel and perform further malicious actions, including remote code execution via scheduler abuse or Twig template evaluation.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-65603 grants an authenticated low-privilege user super-admin access to the Grav content management system. This enables complete control over the Grav instance, allowing the attacker to modify site content, manage users, and potentially achieve remote code execution (RCE) by abusing the scheduler or evaluating Twig templates. The compromise can lead to full system takeover, data exfiltration, defacement, or persistent unauthorized access, severely impacting the integrity, confidentiality, and availability of the affected Grav environment and any hosted applications or data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-65603 by upgrading the Grav Login plugin (grav-plugin-login) to version 3.8.12 or higher immediately.\u003c/li\u003e\n\u003cli\u003eReview the Grav configuration for \u003ccode\u003eplugins.login.user_registration.fields\u003c/code\u003e to ensure that 'groups' and 'access' fields are not inadvertently exposed or enabled for user registration if not strictly required, even after patching.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T12:22:55Z","date_published":"2026-07-22T12:22:55Z","id":"https://feed.craftedsignal.io/briefs/2026-07-grav-login-plugin-privesc/","summary":"A critical privilege escalation vulnerability, CVE-2026-65603, exists in the Grav Login plugin (grav-plugin-login) versions up to and including 3.8.11, allowing an authenticated low-privilege user to exploit a flaw in the `processUserProfile()` handler to bypass privilege stripping and escalate to super-admin, enabling admin panel access, remote code execution, and Twig evaluation.","title":"Grav Login Plugin Privilege Escalation (CVE-2026-65603)","url":"https://feed.craftedsignal.io/briefs/2026-07-grav-login-plugin-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - Grav Login Plugin (Grav-Plugin-Login) \u003c= 3.8.11","version":"https://jsonfeed.org/version/1.1"}