CVE-2025-66296
HIGH EPSS 18.3%
Published Dec 1, 20257mo ago · Modified Jun 17, 20262w ago
8.8 CVSS 3.1
Published Dec 1, 2025 7mo ago
Last Modified Jun 17, 2026 2w ago
Description
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin plugin due to the absence of username uniqueness validation when creating users. A user with the create user permission can create a new account using the same username as an existing administrator account, set a new password/email, and then log in as that administrator. This effectively allows privilege escalation from limited user-manager permissions to full administrator access. This vulnerability is fixed in 1.8.0-beta.27.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High
Threat Intelligence
EPSS Exploit Probability
18.3% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-266
Affected Products 27
| Vendor | Product | Version | Range |
|---|---|---|---|
| getgrav | grav | * | ≥1.7.49.5 – <1.8.0 |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
| getgrav | grav | 1.8.0 | any |
References 2
- github.com https://github.com/getgrav/grav/commit/3462d94d575064601689b236508c316242e15741
- github.com https://github.com/getgrav/grav/security/advisories/GHSA-cjcp-qxvg-4rjm
Remediation
- github.com https://github.com/getgrav/grav/commit/3462d94d575064601689b236508c316242e15741