{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/grav-cms-2.0.14---2.0.24/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-100670"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Grav CMS (2.0.14 - 2.0.24)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Grav"],"content_html":"\u003cp\u003eGrav CMS versions 2.0.14 through 2.0.24 are susceptible to a privilege escalation vulnerability within the handling of group and account blueprints. The vulnerability originates from a flawed security check within \u003ccode\u003eBlueprintSchema::filterArray()\u003c/code\u003e. The system relies on a \u003ccode\u003esecurity@: admin.super\u003c/code\u003e guard to restrict sensitive account modifications, but this guard is incorrectly resolved based on the specific structure of the input key.\u003c/p\u003e\n\u003cp\u003eAn authenticated backend operator, possessing at least 'admin.users' permissions, can submit an account update request using a flat dot-notation key (e.g., \u003ccode\u003eaccess.admin.super\u003c/code\u003e) instead of the expected nested array structure (\u003ccode\u003eaccess[admin][super]\u003c/code\u003e). This malformed key bypasses the blueprint validation rules, enabling the \u003ccode\u003eFlexObject::update()\u003c/code\u003e method to invoke \u003ccode\u003esetNestedProperty()\u003c/code\u003e with the unauthorized value. By exploiting this, an attacker can modify their own account's access level to include \u003ccode\u003eadmin.super\u003c/code\u003e, effectively escalating to full administrative control over the CMS, including plugin/theme installation and file system management. This was remediated in version 2.0.25 by enforcing strict validation on dotted keys.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full super-admin account compromise for an authenticated user with limited backend access. Attackers can gain complete control over the CMS configuration, perform unauthorized plugin and theme installations, access the file manager, and manipulate all other user accounts. This represents a significant risk to the integrity and confidentiality of the entire Grav CMS environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Grav CMS to version 2.0.25 or later immediately to apply the patch for CVE-2026-100670.\u003c/li\u003e\n\u003cli\u003eAudit administrative account activity logs to identify suspicious modifications to user access levels or unauthorized escalation attempts occurring between September 2026 and the time of patching.\u003c/li\u003e\n\u003cli\u003eRestrict access to the backend Flex accounts interface to a strictly controlled set of trusted administrators until the software is updated.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-26T17:00:27Z","date_published":"2026-09-26T17:00:27Z","id":"https://feed.craftedsignal.io/briefs/2026-09-grav-cms-privesc/","summary":"Grav CMS versions 2.0.14 through 2.0.24 contain a privilege escalation vulnerability allowing authenticated backend operators to bypass security guards and grant themselves super-admin privileges.","title":"Privilege Escalation in Grav CMS via Account Blueprint Bypass","url":"https://feed.craftedsignal.io/briefs/2026-09-grav-cms-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - Grav CMS (2.0.14 - 2.0.24)","version":"https://jsonfeed.org/version/1.1"}