CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100670

HIGHCVSS 8.8NVD feed

Published 26 September 2026 · tracked since 27 September 2026

Description

Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` guard that is resolved by the field's exact path, so a submitted flat dot-notation key such as `access.admin.super` (instead of the

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100670 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100670

HIGHCVSS 8.8NVD feed

Published 26 September 2026 · tracked since 27 September 2026

Description

Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` guard that is resolved by the field's exact path, so a submitted flat dot-notation key such as `access.admin.super` (instead of the

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]