CVE-2026-100670: Authorization Bypass Through User-Controlled Key in getgrav grav
Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` guard that is resolved by the field's exact path, so a submitted flat dot-notation key such as `access.admin.super` (instead of the nested `access[admin][super]`) matches no blueprint rule, survives BlueprintSchema::filterArray() and flattening, and is written by FlexObject::update() via setNestedProperty(), which splits on `.` and reconstructs the nested value. An authenticated backend operator using the flex accounts backend who holds admin.users but not admin.super can therefore grant admin.super to their own account or to a group they belong to and escalate to full super-admin, gaining control over configuration, plugin and theme installation, the file manager, and all accounts. Fixed in 2.0.25, which drops any dotted key whose ancestor path is disabled or marked validate.ignore.
AI Analysis
Technical Summary
The vulnerability in Grav CMS 2.0.14 through 2.0.24 arises from the way the system processes access control keys in blueprints. The access map is protected by a security guard 'security@: admin.super' that checks exact paths. However, if a user submits a flat dot-notation key like 'access.admin.super' instead of the nested 'access[admin][super]', it bypasses blueprint validation and filtering. This key is then reconstructed by FlexObject::update() into a nested property, allowing an authenticated backend user with admin.users privileges to grant themselves or their group admin.super rights. This leads to full super-admin access, including control over configuration, plugins, themes, file management, and all accounts. The vulnerability is addressed in version 2.0.25 by rejecting dotted keys with disabled or ignored ancestor paths.
Potential Impact
An authenticated backend user with limited admin.users privileges can escalate their privileges to full super-admin. This grants them unrestricted control over the Grav CMS instance, including configuration changes, plugin and theme installation, file management, and management of all user accounts. This represents a high-severity privilege escalation risk.
Mitigation Recommendations
Upgrade Grav CMS to version 2.0.25 or later, where the vulnerability is fixed by rejecting dotted keys with disabled or ignored ancestor paths. This official fix prevents the privilege escalation. No other mitigation is required.
CVE-2026-100670: Authorization Bypass Through User-Controlled Key in getgrav grav
Description
Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` guard that is resolved by the field's exact path, so a submitted flat dot-notation key such as `access.admin.super` (instead of the nested `access[admin][super]`) matches no blueprint rule, survives BlueprintSchema::filterArray() and flattening, and is written by FlexObject::update() via setNestedProperty(), which splits on `.` and reconstructs the nested value. An authenticated backend operator using the flex accounts backend who holds admin.users but not admin.super can therefore grant admin.super to their own account or to a group they belong to and escalate to full super-admin, gaining control over configuration, plugin and theme installation, the file manager, and all accounts. Fixed in 2.0.25, which drops any dotted key whose ancestor path is disabled or marked validate.ignore.
CVSS v4.0
Score 8.7high
Affected software
getgrav
grav
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Grav CMS 2.0.14 through 2.0.24 arises from the way the system processes access control keys in blueprints. The access map is protected by a security guard 'security@: admin.super' that checks exact paths. However, if a user submits a flat dot-notation key like 'access.admin.super' instead of the nested 'access[admin][super]', it bypasses blueprint validation and filtering. This key is then reconstructed by FlexObject::update() into a nested property, allowing an authenticated backend user with admin.users privileges to grant themselves or their group admin.super rights. This leads to full super-admin access, including control over configuration, plugins, themes, file management, and all accounts. The vulnerability is addressed in version 2.0.25 by rejecting dotted keys with disabled or ignored ancestor paths.
Potential Impact
An authenticated backend user with limited admin.users privileges can escalate their privileges to full super-admin. This grants them unrestricted control over the Grav CMS instance, including configuration changes, plugin and theme installation, file management, and management of all user accounts. This represents a high-severity privilege escalation risk.
Mitigation Recommendations
Upgrade Grav CMS to version 2.0.25 or later, where the vulnerability is fixed by rejecting dotted keys with disabled or ignored ancestor paths. This official fix prevents the privilege escalation. No other mitigation is required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-26T02:34:55.635Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab7c9a9f7a7c5410652fd41
Added to database: 09/26/2026, 13:33:29 UTC
Last enriched: 09/26/2026, 13:49:03 UTC
Last updated: 09/27/2026, 04:31:27 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.