CVE-2026-86195 | GetGrav grav-plugin-api up to 1.0.19 InvitationsController stripSuperFlags privileges management
A vulnerability, which was classified as critical, has been found in GetGrav grav-plugin-api up to 1.0.19. This issue affects the function stripSuperFlags of the component InvitationsController. This manipulation causes improper privilege management.
This vulnerability is tracked as CVE-2026-86195. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More