PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75837 getgrav CVE debrief

CVE-2026-75837 Grav Privilege Escalation via Group Access Field. A delegated admin.users operator can escalate to super-admin by manipulating the access field in the core group blueprint, gaining scheduler and Twig evaluation capabilities. This critical vulnerability affects Grav installations, particularly those with delegated admin.users operators. Administrators and users should assess exposure and update to version 2.0.14 or later to prevent privilege escalation. The vulnerability allows an attacker to save a group with access[admin][super]=true, which can lead to increased risk of scheduler and Twig evaluation capabilities misuse.

Vendor
getgrav
Product
grav
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-09-08
Advisory published
2026-08-18
Advisory updated
2026-09-08

Who should care

Administrators and users of Grav installations, especially those with delegated admin.users operators, should assess exposure and update to version 2.0.14 or later to prevent privilege escalation.

Why it matters

CVE-2026-75837 is a critical vulnerability in Grav before 2.0.14 that allows a delegated admin.users operator to escalate to super-admin, gaining scheduler and Twig evaluation capabilities. Administrators and users of Grav installations should assess exposure and update to version 2.0.14 or later to prevent privilege escalation.

  • Potential privilege escalation to super-admin
  • Increased risk of scheduler and Twig evaluation capabilities misuse
  • Need for review and update of Grav installations to prevent exploitation

Technical summary

The vulnerability in Grav before 2.0.14 allows a delegated admin.users operator to escalate to super-admin by saving a group with access[admin][super]=true, gaining scheduler and Twig evaluation capabilities. This critical vulnerability affects Grav installations, particularly those with delegated admin.users operators. The vulnerability is caused by a lack of proper access control in the core group blueprint, allowing an attacker to manipulate the access field and escalate privileges. Administrators and users of Grav installations should assess exposure and update to version 2.0.14 or later to prevent privilege escalation.

Defensive priority

High

Recommended defensive actions

  • Review and update Grav installations to version 2.0.14 or later
  • Restrict access to the core group blueprint to authorized administrators
  • Monitor for suspicious activity related to group access field modifications
  • Confirm whether affected Grav installations exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in Grav before 2.0.14, where a delegated admin.users operator can escalate to super-admin by manipulating the access field in the core group blueprint.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75837 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75837

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75837 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75837

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.