{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/flex-objects--1.4.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-72831"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Flex Objects (\u003c= 1.4.6)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Grav"],"content_html":"\u003cp\u003eThe Flex Objects plugin for Grav CMS (versions 1.4.6 and earlier) contains an incorrect authorization vulnerability in its API controller. The FlexApiController::update() method fails to enforce sufficient target-specific or field-level permissions, relying instead on broad directory-level checks. This oversight allows an attacker with existing, low-level administrative access (specifically 'api.access', 'admin.login', and 'users.update' permissions) to interact with the '/api/v1/flex-objects/user-accounts' and '/api/v1/flex-objects/user-groups' endpoints. By manipulating these endpoints, an authenticated adversary can reset the password of a super-administrator account or assign the 'admin.super' permission to their own user group. This flaw leads to complete site takeover. The vulnerability is addressed in Flex Objects version 1.4.7.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full administrative site takeover, allowing the attacker to modify site content, configure malicious plugins, access sensitive user data, and execute arbitrary server-side code if the environment permits. This affects any Grav CMS instance running the vulnerable Flex Objects plugin, particularly those where multiple administrative users with varying permission levels exist.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Flex Objects plugin to version 1.4.7 or higher.\u003c/li\u003e\n\u003cli\u003eAudit logs for suspicious activity targeting the '/api/v1/flex-objects/user-accounts' and '/api/v1/flex-objects/user-groups' endpoints, specifically looking for password changes or group membership modifications originating from non-super-admin accounts.\u003c/li\u003e\n\u003cli\u003eReview current user roles and ensure that the 'users.update' permission is only granted to trusted, fully authorized administrative personnel.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T14:12:37Z","date_published":"2026-08-14T14:12:37Z","id":"https://feed.craftedsignal.io/briefs/2026-08-grav-flex-auth/","summary":"An improper authorization vulnerability in the Grav Flex Objects plugin API allows an authenticated user with limited administrative privileges to escalate their access and gain full site control via unauthorized password resets or group privilege modification.","title":"Improper Authorization in Grav Flex Objects Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-grav-flex-auth/"}],"language":"en","title":"CraftedSignal Threat Feed - Flex Objects (\u003c= 1.4.6)","version":"https://jsonfeed.org/version/1.1"}