THREAT OPS › Threat News › [GHSA] GHSA-xhfv-7758-r9hx (high) — Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admin
[GHSA] GHSA-xhfv-7758-r9hx (high) — Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admin
GHSA-xhfv-7758-r9hx Severity: high CVE: CVE-2026-75837
Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admin
## Summary The core Flex group blueprint `system/blueprints/user/group.yaml` (access field, lines 48-55) omits the `security@: admin.super` field guard that its sibling account blueprint carries (`account.yaml:131/138/1
Indicators of compromise
- CVE-2026-75837cve
- CVE-2026-42613cve
Original source: https://github.com/advisories/GHSA-xhfv-7758-r9hx