Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-75837

CRITICAL NVD
CVSS Score 9.1
Severity CRITICAL
Published Aug 18, 2026
Vendor unknown

Description

Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-admin, gaining scheduler and Twig evaluation capabilities.

References