CVE-2026-62235
Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that allows authenticated users with only api.access permission to perform unauthorized CRUD operations on permission-less directories. Attackers with api.access credentials can create, read, update, delete, and export objects from any directory lacking an explicit permissions configuration, bypassing intended authorization controls.
Scoring
- Severity
- LOW
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.29%
- CWE
- CWE-862, CWE-636
- Published
- 2026-07-17
- Last modified
- 2026-07-17
Affected products
- getgrav grav
- getgrav grav
Weakness type
Related vulnerabilities
- CVE-2026-11446 — Booktics – Booking Calendar for Appointments and Service Businesses <= 1.0.23 - Missing Authorization
- CVE-2026-11496 — Woo PDF Invoice Builder <= 2.0.8 - Authenticated (Subscriber+) Insecure Direct Object Reference to Sensitive Order Information Disclosure
- CVE-2026-18121 — Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) in the Calendar block's frontend event dialog (/ccm/calendar/view_event/{bID}/{occurrence_id}).
- CVE-2026-81211 — Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
- CVE-2026-89054 — OpenNMS missing authorization on /api/v2 PATCH endpoints allows unauthenticated configuration changes
- CVE-2026-88959 — Anchor CMS through 0.12.7 Privilege Escalation via Missing Authorization on Admin User-Management Endpoints
- CVE-2026-4129 — Improper Access Controls in NI SystemLink
- CVE-2026-88898 — AppFlowy-Cloud 0.7.2 through 0.9.64 Missing Workspace Authorization on Bulk Publish Endpoint