Broken Access Control in Grav Flex-Objects Affects User Permissions
CVE-2026-62235
2.3LOW
What is CVE-2026-62235?
Grav Flex-Objects versions prior to 1.4.3 exhibit a broken access control vulnerability in the admin-next REST API. This flaw permits authenticated users with only the api.access permission to execute unauthorized Create, Read, Update, and Delete (CRUD) operations on directories that lack explicit permissions configuration. Consequently, attackers with api.access credentials can bypass intended authorization controls, compromising the security of sensitive data stored within unrestricted directories.
Affected Version(s)
grav 0 < 1.4.3
grav 1.4.3
