CVE-2026-62235

Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that allows authenticated users with only api.access permission to perform unauthorized CRUD operations on permission-less directories. Attackers with api.access credentials can create, read, update, delete, and export objects from any directory lacking an explicit permissions configuration, bypassing intended authorization controls.

Scoring

Severity
LOW
CVSS base score
6.3
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
EPSS probability
0.29%
CWE
CWE-862, CWE-636
Published
2026-07-17
Last modified
2026-07-17

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs