PT-2026-58869 · Grav · Flex Objects Plugin
CVE-2026-62670
·
Published
2026-07-14
·
Updated
2026-08-19
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Grav Flex Objects Plugin versions prior to 1.4.3
Description
An issue exists where the
requireFlexPermission() function in classes/Api/FlexApiController.php fails to deny access when a directory blueprint omits config.admin.permissions. This allows an authenticated account with only api.access to bypass the core admin.flex-object. authorization fallback. Consequently, users can utilize the index, show, create, update, delete, export, and media handlers for directories lacking explicit permissions.Recommendations
Update Grav Flex Objects Plugin to version 1.4.3.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flex Objects Plugin