Description
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode that allows users with page-edit access to render any registered Flex collection without permission checks. Attackers can place the shortcode in published pages to expose sensitive directory contents including user account information, bypassing the authorize ACL enforced in the admin panel.
Published: 2026-08-25
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Grav Flex Objects plugin contains an authorization bypass that allows users with page‑edit rights to embed a special shortcode in any page. When processed, the shortcode renders the contents of any registered Flex collection, bypassing the ACL checks that normally restrict access. This enables the viewer to obtain directory listings and user account information that should be protected.

Affected Systems

The flaw affects Grav Flex Objects plugin versions 1.4.0 through 1.4.7. Attackers would need a Grav installation running one of these versions and a user who has page‑edit privileges. The vulnerability is limited to the Grav platform and its Flex Objects plugin.

Risk and Exploitability

With a CVSS score of 8.3, the vulnerability is considered high. The EPSS score is not available and the issue is not in the CISA KEV catalog. The likely attack path requires the attacker to add the problematic shortcode to a page that is publicly visible, so the potential for exploitation is mitigated if page‑edit rights are well protected or restricted to trusted users. Nevertheless, the absence of ACL checks during shortcode rendering makes the vulnerability exploitable whenever an edited page is delivered to a user.

Generated by OpenCVE AI on August 25, 2026 at 03:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Grav Flex Objects to version 1.4.8 or later to eliminate the bypass.
  • Reduce the privileges of users who can edit pages to prevent them from inserting the shortcode.
  • Remove or sanitize any existing flex‑objects shortcodes in published pages until the patch is applied.

Generated by OpenCVE AI on August 25, 2026 at 03:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Description Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode that allows users with page-edit access to render any registered Flex collection without permission checks. Attackers can place the shortcode in published pages to expose sensitive directory contents including user account information, bypassing the authorize ACL enforced in the admin panel.
Title Grav Flex Objects 1.4.0 through 1.4.7 Authorization Bypass via Shortcode
First Time appeared Getgrav
Getgrav grav
Weaknesses CWE-862
CPEs cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*
Vendors & Products Getgrav
Getgrav grav
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-25T01:30:06.601Z

Reserved: 2026-06-22T18:48:27.060Z

Link: CVE-2026-56707

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T02:16:42.637

Modified: 2026-08-25T02:16:42.637

Link: CVE-2026-56707

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T03:30:05Z

Weaknesses