What is CVE-2026-72831?
CVE-2026-72831 is an incorrect authorization vulnerability in the Flex Objects plugin for Grav CMS (up to v1.4.6). The FlexApiController::update() method only verifies the general Flex directory permission and fails to enforce additional target, field, or super-admin checks, potentially allowing unauthorized modifications. It is recommended to disable the plugin until a security update is applied.
Azərbaycanca: CVE-2026-72831, Grav CMS-in Flex Objects pluginində (v1.4.6-dək) aşkar edilmiş səhv avtorizasiya zəifliyidir. Bu boşluq FlexApiController::update() funksiyasında yalnız ümumi Flex qovluq icazəsini yoxlayır, lakin target/field/super-admin kimi əlavə təhlükəsizlik yoxlamalarını tətbiq etmir. Təsirə məruz qalmamaq üçün plugin-i ən son təhlükəsizlik yeniləməsinə qədər müvəqqəti deaktiv etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
In which component of Grav CMS was CVE-2026-72831 discovered?
This vulnerability was discovered in the Flex Objects plugin for Grav CMS, up to version 1.4.6.
What is the security issue caused by CVE-2026-72831?
The FlexApiController::update() method only verifies the general Flex directory permission and fails to enforce additional target, field, or super-admin checks, leading to an incorrect authorization issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.