What is CVE-2026-65603?
The Grav Login plugin (version ≤ 3.8.11) contains a privilege escalation vulnerability. An authenticated user can modify privilege fields like 'access' via the profile self-update handler (`processUserProfile`), potentially gaining admin rights. Updating to the latest version is recommended.
Azərbaycanca: Grav Login plaginində (versiya ≤ 3.8.11) imtiyaz artırma boşluğu aşkarlanıb. Autentifikasiya olunmuş istifadəçi profil yeniləmə funksiyası (`processUserProfile`) vasitəsilə `access` kimi imtiyaz sahələrini dəyişərək admin hüquqları əldə edə bilər. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
Which versions of the Grav Login plugin are affected by the CVE-2026-65603 privilege escalation vulnerability?
Grav Login plugin versions 3.8.11 and earlier are affected by this vulnerability.
How can an authenticated user gain admin rights by exploiting CVE-2026-65603?
An authenticated user can gain admin rights by modifying privilege fields like 'access' via the profile self-update handler (`processUserProfile`).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.