Authorization Bypass Vulnerability in Grav Flex Objects Plugin by Grav
CVE-2026-56707
8.3HIGH
What is CVE-2026-56707?
The Grav Flex Objects plugin, versions 1.4.0 to 1.4.7, is susceptible to an authorization bypass vulnerability. This flaw exists within the 'flex-objects' shortcode, which permits users with page-editing privileges to render any registered Flex collection without appropriate permission checks. Consequently, malicious actors can exploit this weakness by embedding the shortcode on published pages, leading to the unauthorized exposure of sensitive directory contents, including user account data. This vulnerability undermines the access control list (ACL) typically enforced within the administration panel.
Affected Version(s)
grav 0 < 1.4.8
grav 1.4.8
