CRITICAL 9.1 CVE-2026-75837 Published 18 Aug 2026

Grav CMS Privilege Escalation Vulnerability

Worried this affects one of your servers?

Grav before 2.0.14 contains a privilege escalation vulnerability in its core group blueprint. The access field is not guarded by the required security@: admin.super restriction.

A delegated admin.users operator can save a group with access[admin][super]=true, escalating to super-admin and gaining scheduler and Twig evaluation capabilities.

  • Affected versions: Grav before 2.0.14
  • Impact: privilege escalation to super-admin, scheduler and Twig evaluation capabilities

Reference: CVE-2026-75837 on NVD

← Back to Security News