CVE-2026-86196
Received Received - Intake

Grav API Plugin Password Reset Host Header Injection

Vulnerability report for CVE-2026-86196, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-05

Last updated on: 2026-09-05

Assigner: VulnCheck

Description

Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can send password reset requests for any account with a malicious Host header, intercept the reset token from victim emails, and complete account takeover including super-admin accounts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-05
Last Modified
2026-09-05
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
getgrav grav_api_plugin to 1.0.20 (exc)
grav api_plugin to 1.0.20 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Grav API Plugin versions before 1.0.20. It allows unauthenticated attackers to bypass authentication by manipulating password reset links. The plugin uses the untrusted Host header to construct reset links, enabling attackers to redirect reset tokens to their own domains. Victims receive spoofed reset emails with malicious links, allowing attackers to intercept tokens and take over accounts, including super-admins.

Detection Guidance

To detect this vulnerability, inspect HTTP requests to the Grav API plugin's forgot-password endpoint for Host header manipulation. Check if reset links in emails use attacker-controlled domains. Monitor for unusual password reset requests or tokens being sent to external servers.

Impact Analysis

Attackers can take over any user account, including super-admins, by intercepting password reset tokens. This leads to full account compromise, data theft, unauthorized access, and potential site takeover. Users of vulnerable Grav API Plugin versions are at risk of losing control of their accounts and sensitive data.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR and HIPAA requirements for data protection and access control. Organizations may face compliance violations, legal penalties, and reputational damage due to data breaches resulting from this flaw.

Mitigation Strategies

Immediately update the Grav API plugin to version 1.0.20 or later. As a temporary workaround, set a custom base URL in Grav's system configuration to override the Host header. Block or monitor outbound connections to unexpected domains from your email server.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86196. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart