Impact
Grav Flex‑Objects before version 1.4.3 contains a broken access control flaw in the admin‑next REST API. Authenticated users that only possess the "api.access" permission can create, read, update, delete, and export objects from any directory that has no explicit permissions set. This weakness allows attackers to perform CRUD operations on data beyond the intended scope, effectively bypassing authorization controls. The vulnerability corresponds to CWE‑636 and CWE‑862.
Affected Systems
The issue affects the Grav CMS by getgrav, specifically the Flex‑Objects plugin when installed at a version lower than 1.4.3. Any directories configured within the plugin that lack an explicit permissions configuration are vulnerable, regardless of the overall site configuration.
Risk and Exploitability
The CVSS score of 2.3 reflects a low risk severity, and the EPSS score of <1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authentication with api.access credentials and access to the admin‑next API, which limits the attack surface but still permits unauthorized data modification or exposure in the affected directories.
OpenCVE Enrichment