Authorization Bypass Vulnerability in Grav Flex Objects Plugin by Grav
CVE-2026-56707

8.3HIGH

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-56707?

The Grav Flex Objects plugin, versions 1.4.0 to 1.4.7, is susceptible to an authorization bypass vulnerability. This flaw exists within the 'flex-objects' shortcode, which permits users with page-editing privileges to render any registered Flex collection without appropriate permission checks. Consequently, malicious actors can exploit this weakness by embedding the shortcode on published pages, leading to the unauthorized exposure of sensitive directory contents, including user account data. This vulnerability undermines the access control list (ACL) typically enforced within the administration panel.

Affected Version(s)

grav 0 < 1.4.8

grav 1.4.8

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

alham-rizvi
.