CVE-2026-86195 | GetGrav grav-plugin-api up to 1.0.19 InvitationsController stripSuperFlags privileges management

SecurityVulns

A vulnerability, which was classified as critical, has been found in GetGrav grav-plugin-api up to 1.0.19. This issue affects the function stripSuperFlags of the component InvitationsController. This manipulation causes improper privilege management.

This vulnerability is tracked as CVE-2026-86195. The attack is possible to be carried out remotely. No exploit exists.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More