PT-2026-99341 · Grav Cms · Grav Cms

·

CVE-2026-100670

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grav CMS versions 2.0.14 through 2.0.24
Description A privilege escalation issue exists in the group and account blueprints. The access map is protected by a security@: admin.super guard resolved by the field's exact path. An authenticated backend operator using the flex accounts backend with admin.users permissions, but lacking admin.super, can bypass blueprint rules by submitting a flat dot-notation key like access.admin.super instead of the nested access[admin][super]. This input survives BlueprintSchema::filterArray() and flattening, and is subsequently processed by FlexObject::update() via setNestedProperty(), which splits the dot-notation and reconstructs the nested value. This allows the operator to grant admin.super status to their own account or a group they belong to, resulting in full super-admin control over configuration, plugin and theme installation, the file manager, and all accounts.
Recommendations Update Grav CMS to version 2.0.25.

Exploit

Fix

LPE

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100670
GHSA-MWJJ-R7VM-PGQM

Affected Products

Grav Cms