CVE-2026-56707

Source
https://cve.org/CVERecord?id=CVE-2026-56707
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-56707.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-56707
Aliases
  • GHSA-x929-528m-vx2m
Published
2026-08-25T01:30:06.601Z
Modified
2026-08-28T03:30:17.466484752Z
Severity
  • 8.3 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N CVSS Calculator
Summary
Grav Flex Objects 1.4.0 through 1.4.7 Authorization Bypass via Shortcode
Details

Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode that allows users with page-edit access to render any registered Flex collection without permission checks. Attackers can place the shortcode in published pages to expose sensitive directory contents including user account information, bypassing the authorize ACL enforced in the admin panel.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56707.json",
    "cwe_ids": [
        "CWE-862"
    ],
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/getgrav/grav

Affected ranges

Type
GIT
Repo
https://github.com/getgrav/grav
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.4.8"
        },
        {
            "introduced": "1.4.0"
        },
        {
            "fixed": "1.4.7"
        }
    ]
}

Affected versions

1.*
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-56707.json"