CVE-2026-72825 | GetGrav up to 1.0.12 ReportsController allowlist isSuperAdmin privileges management

SecurityVulns

A vulnerability classified as critical was found in GetGrav Grav up to 1.0.12. This issue affects the function isSuperAdmin of the file /reports/twig-content/allowlist of the component ReportsController. Executing a manipulation can lead to improper privilege management.

This vulnerability appears as CVE-2026-72825. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is advised.VulDB Recent EntriesRead More