PT-2025-48555 · Unknown+1 · Grav Admin Plugin+1

Published

2025-12-01

·

Updated

2025-12-01

·

CVE-2025-66296

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grav versions prior to 1.8.0-beta.27
Description Grav’s Admin plugin contains a flaw where the creation of new user accounts does not validate username uniqueness. This allows a user with create user permission to create an account with the same username as an existing administrator account, effectively gaining administrator access through privilege escalation. The username is not properly validated during account creation, allowing an attacker to overwrite administrator credentials with a new password and email.
Recommendations Update to Grav version 1.8.0-beta.27 or later.

Exploit

Fix

LPE

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66296
GHSA-CJCP-QXVG-4RJM

Affected Products

Grav
Grav Admin Plugin