{"id":"CVE-2026-75837","title":"Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction","summary":"Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-ad…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-269","CWE-862"],"published":"2026-08-18","updated":"2026-09-08","sourceUpdated":"2026-09-08T20:32:39.347","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-75837","references":[{"url":"https://github.com/getgrav/grav/security/advisories/GHSA-xhfv-7758-r9hx","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/grav-before-privilege-escalation-via-group-access-field","label":"disclosure@vulncheck.com"},{"url":"https://github.com/getgrav/grav/security/advisories/GHSA-xhfv-7758-r9hx","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75837"},{"url":"https://github.com/advisories/GHSA-xhfv-7758-r9hx"}],"tags":["nvd","ghsa","composer"],"epss":0.00339,"epssPercentile":0.27444,"ingestedAt":"2026-09-08T21:11:12.280Z","aliases":["GHSA-xhfv-7758-r9hx"],"ecosystem":"composer","vendor":"getgrav","product":"getgrav/grav","affected":["getgrav/grav < 2.0.14"],"patched":["getgrav/grav 2.0.14"],"slug":"CVE-2026-75837","body":"## Overview\n\nGrav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-admin, gaining scheduler and Twig evaluation capabilities.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-75837)\n\nAffected packages:\n\n- `getgrav/grav < 2.0.14`\n\nPatched in:\n\n- `getgrav/grav 2.0.14`\n\nSource: https://github.com/advisories/GHSA-xhfv-7758-r9hx","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}