{"id":"CVE-2026-42609","aliases":["GHSA-rr73-568v-28f8"],"url":"https://o3.security/vulnerability/CVE-2026-42609","summary":"Grav: Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic","details":"Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows a low-privileged user (with only user creation permissions) to overwrite existing accounts, including the primary administrator. By creating a new user with a username that already exists, the system updates the existing account's metadata and permissions instead of rejecting the request. This leads to a Denial of Service (DoS) on administrative functions and Privilege De-escalation of the root account. This vulnerability is fixed in 2.0.0-beta.2.","published":"2026-05-11T15:03:38.296Z","modified":"2026-08-07T11:50:18.479607041Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"getgrav/grav","fixedVersion":"2.0.0-beta.2"}],"fix":{"url":"https://github.com/getgrav/grav/commit/5a12f9be8314682c8713e569e330f11805d0a663","label":"getgrav/grav@5a12f9b"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42609.json"},{"type":"ADVISORY","url":"https://github.com/getgrav/grav/security/advisories/GHSA-rr73-568v-28f8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42609"},{"type":"FIX","url":"https://github.com/getgrav/grav/commit/5a12f9be8314682c8713e569e330f11805d0a663"},{"type":"FIX","url":"https://github.com/getgrav/grav/commit/c66dfeb5ff679a1667678c6335eb9ff3255dfc47"},{"type":"FIX","url":"https://github.com/getgrav/grav/commit/d904efc33e03ebb597afde8d3368b28cf0423632"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:50:18.479607041Z"}}