Impact
Grav’s core group blueprint does not enforce the required security permission on the access field. A delegated admin.users operator can create or modify a group to set admin.super to true, granting that operator super‑admin rights that enable scheduler usage and Twig template evaluation. This flaw is a classic privilege‑escalation weakness, classified as CWE‑269.
Affected Systems
The vulnerability affects Grav distributed by getgrav, specifically any installation that has not yet been updated to release 2.0.14. All earlier versions, regardless of deployment environment, are susceptible.
Risk and Exploitability
With a CVSS score of 9.3 the flaw is considered critical. EPSS is not available and the issue is not listed in CISA’s KEV catalog, indicating no public exploitation data yet. However, the attack can be performed by an authenticated user who has delegated admin.users privileges, a realistic condition in many Grav deployments. Based on the description, the likely attack vector is an authenticated user with such delegated permissions.
OpenCVE Enrichment