CVE-2026-86196
nicheHost header injection in Grav API plugin enables unauthenticated account takeover
Grav API plugin versions before 1.0.20 build password reset links using the untrusted Host header from the forgot-password request, a host header injection flaw (CWE-290) sometimes called password-reset poisoning. An unauthenticated attacker can submit a reset request for any account with a malicious Host header, causing the reset email to contain a link pointing to an attacker-controlled domain instead of the legitimate site. By intercepting the reset token from the victim's email, the attacker can set a new password and achieve full account takeover, including super-admin accounts. Any Grav CMS site running the API plugin in an affected version is exposed. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation has been reported, and EPSS estimates only about a 0.3% chance of exploitation within 30 days.
What to do: Upgrade the Grav API plugin to version 1.0.20 or later. As an interim mitigation, enforce a Host header allowlist at the web server or reverse proxy and review password-reset emails for links to unexpected domains; consider disabling the forgot-password endpoint or the plugin until patched.
| Grav (getgrav) API plugin | all versions before 1.0.20 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can send password reset requests for any account with a malicious Host header, intercept the reset token from victim emails, and complete account takeover including super-admin accounts.
- Weakness
- CWE-290
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.