CRITICAL
9.1 CVE-2026-75837 Published 18 Aug 2026
Grav CMS Privilege Escalation Vulnerability
Worried this affects one of your servers?
Grav before 2.0.14 contains a privilege escalation vulnerability in its core group blueprint. The access field is not guarded by the required security@: admin.super restriction.
A delegated admin.users operator can save a group with access[admin][super]=true, escalating to super-admin and gaining scheduler and Twig evaluation capabilities.
- Affected versions: Grav before 2.0.14
- Impact: privilege escalation to super-admin, scheduler and Twig evaluation capabilities
Reference: CVE-2026-75837 on NVD
← Back to Security News