PT-2026-76937 · Grav · Grav
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Grav versions prior to 2.0.14
Description
An issue exists where the access field in the core group blueprint is not properly guarded by the
security@: admin.super restriction. This allows a delegated admin.users operator to escalate their privileges to super-admin by saving a group with the access[admin][super] variable set to true. Upon escalation, the user gains capabilities for scheduler management and Twig evaluation, which is a template engine used to generate HTML.Recommendations
Update Grav to version 2.0.14 or later.
Exploit
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav