CVE-2026-42609CWE-269CWE-285CWE-639CWE-837

Grav: Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic

High · published May 11, 2026

CVSS v3.1
8.1
EPSS
0%
Percentile
38.6
In the wild
Unconfirmed
What it is

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows a low-privileged user (with only user creation permissions) to overwrite existing accounts, including the primary administrator. By creating a new user with a username that already exists, the system updates the existing account's metadata and permissions instead of rejecting the request. This leads to a Denial of Service (DoS) on administrative functions and Privilege De-escalation of the root account. This vulnerability is fixed in 2.0.0-beta.2.

The record
Technical detail
CVSS v3.1
8.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00463 · 38.6th percentile
Weaknesses
CWE-269 · Improper Privilege Management; CWE-285 · Improper Authorization; CWE-639 · Authorization Bypass Through User-Controlled Key; CWE-837 · Improper Enforcement of a Single, Unique Action
Published
2026-05-11T15:03Z
EPSS history
Timeline
  • 11 MAY 15:03Z
    Grav: Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic
    cvelistv5