A vulnerability, which was classified as critical, was found in getgrav Login Plugin up to 3.8.11. The affected element is the function
processUserProfile of the component Authenticated Profile Self-Update Handler. Executing a manipulation of the argument groups/access can lead to improper privilege management.
This vulnerability is registered as CVE-2026-65603. It is possible to launch the attack remotely. No exploit is available.