CVE-2026-75837
CRITICAL
NVD
CVSS Score
9.1
Severity
CRITICAL
Published
Aug 18, 2026
Vendor
unknown
Description
Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-admin, gaining scheduler and Twig evaluation capabilities.