NVD CRITICAL: CVE-2026-75837 — Grav before 2.0.14 fails to guard the access field in the core group blueprint w...
Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-admin, gaining scheduler and Twig evaluation capabilities.
CVE-2026-75837