What is CVE-2026-62670?
CVE-2026-62670 is an improper access control vulnerability in Grav Flex Objects plugin before version 1.4.3. The `requireFlexPermission()` method in `FlexApiController.php` fails to deny access when a directory blueprint lacks `config.admin.permissions`, allowing an authenticated user to bypass restrictions. Upgrading the plugin to the latest version is recommended.
Azərbaycanca: CVE-2026-62670 Grav Flex Objects pluginində (1.4.3 versiyasından əvvəl) icazə yoxlamasında boşluqdur. `FlexApiController.php` faylındakı `requireFlexPermission()` metodu, directory blueprint-də `config.admin.permissions` parametri çatışmadıqda autentifikasiyalı istifadəçiyə girişi səhvən bloklamır. Plugin-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What is CVE-2026-62670 and which plugin does it affect?
CVE-2026-62670 is an improper access control vulnerability in the Grav Flex Objects plugin before version 1.4.3. The `requireFlexPermission()` method in `FlexApiController.php` fails to deny access when a directory blueprint lacks `config.admin.permissions`, allowing an authenticated user to bypass restrictions.
How to remediate the CVE-2026-62670 vulnerability?
To remediate CVE-2026-62670, it is recommended to upgrade the Grav Flex Objects plugin to the latest version (1.4.3 or higher).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.