8.8
CVE-2026-72831
- EPSS 0.3%
- Veröffentlicht 14.08.2026 11:35:37
- Zuletzt bearbeitet 18.08.2026 02:17:28
- CVE-Watchlists
- Unerledigt
Grav through 2.0.11 Authentication Bypass via Flex Objects
The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiController::update() checks only the general Flex directory permission and does not apply the additional target/field/super-admin checks enforced by the dedicated Users and Groups API controllers. An authenticated account with api.access, admin.login, and users.update permissions (but without api.users.write or admin.super) can use the generic /api/v1/flex-objects/user-accounts endpoint to change a super administrator's password, or the /api/v1/flex-objects/user-groups endpoint to grant its group admin.super, resulting in full site takeover. Fixed in Flex Objects 1.4.7.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellergetgrav
≫
Produkt
grav
Default Statusunaffected
Version <=
2.0.11
Version
2.0.11
Status
affected
Herstellergetgrav
≫
Produkt
grav
Default Statusunaffected
Version
0
Version <
1.4.7
Status
affected
Version
1.4.7
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.228 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://github.com/getgrav/grav/commit/ad9709f865b09b68798fb1ac375b484a8cc1d892
https://github.com/getgrav/grav/security/advisories/GHSA-pc8m-jxvh-vmrc
https://github.com/getgrav/grav/commit/0b384f5b0e73b1ad9dd29c70185407895ea3b09f
https://github.com/getgrav/grav/commit/8071c10bc3a4743a4b8cf003dfb1644d6680c2ea
https://github.com/getgrav/grav/commit/a0bf26f7e5d7a98894b7cd2b8c5afe419b264e53
https://www.vulncheck.com/advisories/grav-through-authentication-bypass-via-flex-objects