Product
high
advisory
Grav Privilege Escalation via Group Blueprint ACL Bypass
1 rule 3 TTPs 1 CVEA missing 'security@' guard in Grav's group blueprint allows an 'admin.users' operator to escalate privileges to 'admin.super' by modifying group access configurations.
Grav +2
privilege-escalation
cms
vulnerability
web-application-vulnerability
path-traversal
cve-2026-74907
twig
security-misconfiguration
1r
3t
1c
high
advisory
Grav CMS Twig Sandbox Bypass via Configuration Exposure
3 TTPs 1 CVECVE-2026-92917 allows an authenticated user with page-edit privileges in Grav CMS 2.0.0-rc.1 through 2.0.21 to bypass Twig sandboxing and exfiltrate the full application configuration, including API keys and credentials.
Grav +1
cms
web-application
security-misconfiguration
information-disclosure
3t
1c
updated