CVE Vulnerabilities

CVE-2025-66296

Incorrect Privilege Assignment

Published: Dec 01, 2025 | Modified: Dec 04, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin plugin due to the absence of username uniqueness validation when creating users. A user with the create user permission can create a new account using the same username as an existing administrator account, set a new password/email, and then log in as that administrator. This effectively allows privilege escalation from limited user-manager permissions to full administrator access. This vulnerability is fixed in 1.8.0-beta.27.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Grav Getgrav 1.7.49.5 (including) 1.8.0 (excluding)
Grav Getgrav 1.8.0-beta1 (including) 1.8.0-beta1 (including)
Grav Getgrav 1.8.0-beta10 (including) 1.8.0-beta10 (including)
Grav Getgrav 1.8.0-beta11 (including) 1.8.0-beta11 (including)
Grav Getgrav 1.8.0-beta12 (including) 1.8.0-beta12 (including)
Grav Getgrav 1.8.0-beta13 (including) 1.8.0-beta13 (including)
Grav Getgrav 1.8.0-beta14 (including) 1.8.0-beta14 (including)
Grav Getgrav 1.8.0-beta15 (including) 1.8.0-beta15 (including)
Grav Getgrav 1.8.0-beta16 (including) 1.8.0-beta16 (including)
Grav Getgrav 1.8.0-beta17 (including) 1.8.0-beta17 (including)
Grav Getgrav 1.8.0-beta18 (including) 1.8.0-beta18 (including)
Grav Getgrav 1.8.0-beta19 (including) 1.8.0-beta19 (including)
Grav Getgrav 1.8.0-beta2 (including) 1.8.0-beta2 (including)
Grav Getgrav 1.8.0-beta20 (including) 1.8.0-beta20 (including)
Grav Getgrav 1.8.0-beta21 (including) 1.8.0-beta21 (including)
Grav Getgrav 1.8.0-beta22 (including) 1.8.0-beta22 (including)
Grav Getgrav 1.8.0-beta23 (including) 1.8.0-beta23 (including)
Grav Getgrav 1.8.0-beta24 (including) 1.8.0-beta24 (including)
Grav Getgrav 1.8.0-beta25 (including) 1.8.0-beta25 (including)
Grav Getgrav 1.8.0-beta26 (including) 1.8.0-beta26 (including)
Grav Getgrav 1.8.0-beta3 (including) 1.8.0-beta3 (including)
Grav Getgrav 1.8.0-beta4 (including) 1.8.0-beta4 (including)
Grav Getgrav 1.8.0-beta5 (including) 1.8.0-beta5 (including)
Grav Getgrav 1.8.0-beta6 (including) 1.8.0-beta6 (including)
Grav Getgrav 1.8.0-beta7 (including) 1.8.0-beta7 (including)
Grav Getgrav 1.8.0-beta8 (including) 1.8.0-beta8 (including)
Grav Getgrav 1.8.0-beta9 (including) 1.8.0-beta9 (including)

Potential Mitigations

References