CVE-2026-86196CWE-290

CVE-2026-86196

published September 5, 2026

CVSS
8.7
EPSS
In the wild
Unconfirmed
What it is

Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can send password reset requests for any account with a malicious Host header, intercept the reset token from victim emails, and complete account takeover including super-admin accounts.

The record
Technical detail
CVSS
8.7 · NONE
CVSS v4.0
8.7 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
Not scored
Weakness
CWE-290 · Authentication Bypass by Spoofing
Published
2026-09-05T17:18Z
References (2)
Timeline
  • 05 SEP 12:09Z
    Grav API Plugin before 1.0.20 Authentication Bypass via Host Header
    cvelistv5