{"id":"CVE-2026-62670","title":"Grav Flex Objects Plugin allows you to build custom collections of objects","summary":"Grav Flex Objects Plugin allows you to build custom collections of objects. Prior to 1.4.3, the Grav Flex Objects Admin Next API requireFlexPermission() method in classes/Api/FlexApiController.php returns without denying access when a di…","severity":"medium","cvss":6.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-862"],"published":"2026-08-19","updated":"2026-09-09","sourceUpdated":"2026-09-09T21:13:25.910","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-62670","references":[{"url":"https://github.com/getgrav/grav/security/advisories/GHSA-23vq-365v-qcmh","label":"security-advisories@github.com"},{"url":"https://github.com/trilbymedia/grav-plugin-flex-objects/commit/198d1a0eb7b94777a026ed0001d9a369d94c3002","label":"security-advisories@github.com"},{"url":"https://github.com/trilbymedia/grav-plugin-flex-objects/releases/tag/1.4.3","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00244,"epssPercentile":0.15854,"ingestedAt":"2026-09-09T21:22:45.540Z","slug":"CVE-2026-62670","body":"## Overview\n\nGrav Flex Objects Plugin allows you to build custom collections of objects. Prior to 1.4.3, the Grav Flex Objects Admin Next API requireFlexPermission() method in classes/Api/FlexApiController.php returns without denying access when a directory blueprint omits config.admin.permissions. An authenticated account with only api.access can use the index, show, create, update, delete, export, and media handlers for a permission-less directory even though the core admin.flex-object. authorization fallback would deny the same actions. This issue is fixed in version 1.4.3.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}