Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode handler. Users with page-edit access can render any registered Flex collection without proper permission checks. Attackers can embed the shortcode in published pages to expose sensitive directory contents, including user account information. The vulnerability bypasses the authorize ACL enforced in the admin panel. This represents a privilege escalation risk where lower-privileged users can access data beyond their authorization scope. The flaw is specifically tied to the shortcode rendering path, which lacks the same access controls applied elsewhere. Organizations running affected versions of the plugin on Grav CMS installations should prioritize patching. References include the NVD entry, a GitHub security advisory, and a VulnCheck advisory.