A vulnerability has been found in GetGrav Grav up to 1.4.6 and classified as problematic. Affected is the function FlexApiController::update of the component Flex Objects API. Performing a manipulation results in improper authorization.

This vulnerability is known as CVE-2026-72831. Remote exploitation of the attack is possible. No exploit is available.

The affected component should be upgraded.