PT-2026-99341 · Grav Cms · Grav Cms
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Grav CMS versions 2.0.14 through 2.0.24
Description
A privilege escalation issue exists in the group and account blueprints. The access map is protected by a
security@: admin.super guard resolved by the field's exact path. An authenticated backend operator using the flex accounts backend with admin.users permissions, but lacking admin.super, can bypass blueprint rules by submitting a flat dot-notation key like access.admin.super instead of the nested access[admin][super]. This input survives BlueprintSchema::filterArray() and flattening, and is subsequently processed by FlexObject::update() via setNestedProperty(), which splits the dot-notation and reconstructs the nested value. This allows the operator to grant admin.super status to their own account or a group they belong to, resulting in full super-admin control over configuration, plugin and theme installation, the file manager, and all accounts.Recommendations
Update Grav CMS to version 2.0.25.
Exploit
Fix
LPE
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav Cms