CVE-2026-56707
Received Received - Intake

Authorization Bypass in Grav Flex Objects Plugin

Vulnerability report for CVE-2026-56707, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: VulnCheck

Description

Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode that allows users with page-edit access to render any registered Flex collection without permission checks. Attackers can place the shortcode in published pages to expose sensitive directory contents including user account information, bypassing the authorize ACL enforced in the admin panel.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
getgrav flex_objects 1.4.0
getgrav flex_objects to 1.4.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Grav Flex Objects plugin versions 1.4.0 through 1.4.7 has an authorization bypass vulnerability in the flex-objects shortcode. Users with page-edit access can render any registered Flex collection without permission checks, exposing sensitive directory contents like user account information by bypassing admin panel ACLs.

Detection Guidance

Check if the Grav Flex Objects plugin version is between 1.4.0 and 1.4.7. Use commands like 'composer show | grep flex-objects' or inspect the plugin directory for version details. Look for unauthorized use of the [flex-objects] or [flex] shortcode in published pages.

Impact Analysis

Attackers with page-edit access can place the shortcode in published pages to expose sensitive data such as user account information, including usernames, emails, and permissions. This bypasses Grav 2.0's security measures and could lead to unauthorized data exposure if default templates are used.

Compliance Impact

This vulnerability could lead to unauthorized exposure of personal data, potentially violating GDPR and HIPAA compliance requirements for data protection and access controls. Organizations using affected versions may face regulatory penalties due to insufficient authorization checks.

Mitigation Strategies

Upgrade the Grav Flex Objects plugin to version 1.4.8 or later. Restrict page-edit permissions to trusted users only. Temporarily disable the Shortcode Core plugin if not required. Review published pages for unauthorized use of the vulnerable shortcode.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56707. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart