CVE Feed

    Dashboard / CVE / CVE-2026-62669

    CVE-2026-62669

    Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.regenerate2FASecret task checks only that the pending-session user exists rather than requiring $user->authorized. After submitting a victim's correct password, an attacker can invoke taskRegenerate2FASecret() during the pending TOTP challenge, overwrite twofa_secret, read the replacement secret from the response, calculate a valid code, and complete authentication without the victim's second factor. This issue is fixed in version 3.8.11.

    Published:Aug 19, 2026
    Last Modified:Aug 21, 2026
    EPS:Aug 19, 2026
    EPSS Score:0.00386
    CVSS Score:7.4

    Affected Products

    Vendor
    Getgrav
    Product
    Grav
    Vendor
    Getgrav
    Product
    Grav-plugin-admin

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High