This advisory has been withdrawn because it is a duplicate of GHSA-xhfv-7758-r9hx. This link is maintained to preserve external references.
Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-admin, gaining scheduler and Twig evaluation capabilities.
{
"cwe_ids": [
"CWE-269"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-17T20:44:49Z",
"nvd_published_at": "2026-08-18T12:19:33Z",
"severity": "CRITICAL"
}