NVD HIGH: CVE-2026-100670 — Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in ...
Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` guard that is resolved by the field's exact path, so a submitted flat dot-notation key such as `access.admin.super` (instead of the nested `access[admin][super]`) matches no blueprint rule, survives BlueprintSchema::filterArray() an
CVE-2026-100670