CVE-2026-72831
published 2026-08-14CVE-2026-72831: The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API…
PriorityP258high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.30%
22.4th percentile
The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiController::update() checks only the general Flex directory permission and does not apply the additional target/field/super-admin checks enforced by the dedicated Users and Groups API controllers. An authenticated account with api.access, admin.login, and users.update permissions (but without api.users.write or admin.super) can use the generic /api/v1/flex-objects/user-accounts endpoint to change a super administrator's password, or the /api/v1/flex-objects/user-groups endpoint to grant its group admin.super, resulting in full site takeover. Fixed in Flex Objects 1.4.7.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| getgrav | grav | < 1.4.7 | 1.4.7 |
| getgrav | grav | 2.0.11 – 2.0.11 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GetGrav up to 1.4.6 Flex Objects API update improper authorization (EUVD-2026-58645)
vuldb·2026-08-28·CVSS 8.8
CVE-2026-72831 [HIGH] GetGrav up to 1.4.6 Flex Objects API update improper authorization (EUVD-2026-58645)
A vulnerability has been found in GetGrav Grav up to 1.4.6 and classified as problematic. Affected is the function FlexApiController::update of the component Flex Objects API. Performing a manipulation results in improper authorization.
This vulnerability is known as CVE-2026-72831. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
GHSA
The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API.
ghsa_unreviewed·2026-08-14
CVE-2026-72831 [HIGH] CWE-863 The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API.
The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiController::update() checks only the general Flex directory permission and does not apply the additional target/field/super-admin checks enforced by the dedicated Users and Groups API controllers. An authenticated account with api.access, admin.login, and users.update permissions (but without api.users.write or admin.super) can use the generic /api/v1/flex-objects/user-accounts endpoint to change a super administrator's password, or the /api/v1/flex-objects/user-groups endpoint to grant its group admin.super, resulting in full site takeover. Fixed in Flex Objects 1.4.7.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/getgrav/grav-plugin-admin2/commit/a0bf26f7e5d7a98894b7cd2b8c5afe419b264e53https://github.com/getgrav/grav-plugin-api/commit/8071c10bc3a4743a4b8cf003dfb1644d6680c2eahttps://github.com/getgrav/grav/commit/ad9709f865b09b68798fb1ac375b484a8cc1d892https://github.com/getgrav/grav/security/advisories/GHSA-pc8m-jxvh-vmrchttps://github.com/trilbymedia/grav-plugin-flex-objects/commit/0b384f5b0e73b1ad9dd29c70185407895ea3b09fhttps://www.vulncheck.com/advisories/grav-through-authentication-bypass-via-flex-objectshttps://github.com/getgrav/grav/security/advisories/GHSA-pc8m-jxvh-vmrc
2026-08-14
Published