What is CVE-2026-75837?
CVE-2026-75837 is a privilege escalation vulnerability in Grav CMS before version 2.0.14 where the 'access' field in the core group blueprint lacks the required admin.super restriction. A delegated admin.users operator can exploit this to escalate to super-admin, gaining scheduler and Twig evaluation capabilities. Upgrading to Grav 2.0.14 or later is recommended.
Azərbaycanca: CVE-2026-75837 Grav CMS-in 2.0.14-dən əvvəlki versiyalarında "core group blueprint"-də "access" sahəsinin admin.super məhdudiyyəti ilə qorunmaması səbəbindən imtiyaz yüksəltmə zəifliyidir. admin.users icazəsinə malik istifadəçi bu qüsurdan istifadə edərək özünü super-admin edə bilər. Grav-i 2.0.14 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
What platform is affected by CVE-2026-75837?
CVE-2026-75837 affects Grav CMS versions before 2.0.14.
How can a user with admin.users permission exploit CVE-2026-75837?
A user with admin.users permission can exploit this flaw by escalating themselves to super-admin because the 'access' field in the core group blueprint lacks the required admin.super restriction.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.