CVE-2026-62232
published 2026-07-17CVE-2026-62232: Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence…
PriorityP353high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.28%
20.5th percentile
Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence, not authorization, during the pending TOTP challenge window. Attackers who know the victim's password can call this task without a CSRF nonce to overwrite the 2FA secret with an attacker-chosen value, compute a valid TOTP code, and complete authentication while reducing 2FA to password-only protection.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| getgrav | grav | < 2.0.4 | 2.0.4 |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv4.09.1CRITICALCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
getgrav Grav up to 2.0.3 Login Plugin regenerate2FASecret 2FA secret cross-site request forgery
vuldb·2026-07-17
CVE-2026-62232 [LOW] getgrav Grav up to 2.0.3 Login Plugin regenerate2FASecret 2FA secret cross-site request forgery
A vulnerability was found in getgrav Grav up to 2.0.3. It has been rated as problematic. This impacts the function regenerate2FASecret of the component Login Plugin. This manipulation of the argument 2FA secret causes cross-site request forgery.
The identification of this vulnerability is CVE-2026-62232. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence, not authorization, during the pending TOT
ghsa_unreviewed·2026-07-17
CVE-2026-62232 [CRITICAL] CWE-862 Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence, not authorization, during the pending TOT
Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence, not authorization, during the pending TOTP challenge window. Attackers who know the victim's password can call this task without a CSRF nonce to overwrite the 2FA secret with an attacker-chosen value, compute a valid TOTP code, and complete authentication while reducing 2FA to password-only protection.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-17
Published