CVE-2026-62671: Getgrav Grav-Plugin-Login
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.regenerate2FASecret task accepts a top-level GET request through the TaskServiceProvider task: URI parameter without requiring a login-form nonce, an Origin check, or a Referer check. Under the default SameSite=Lax session cookie policy, an off-site navigation can invoke taskRegenerate2FASecret() in a logged-in victim's session, overwrite the victim's TOTP secret, and force two-factor re-enrollment. This issue is fixed in version 3.8.11.
Affected products
- Getgrav Grav-Plugin-Login: before 3.8.11 (fixed in 3.8.11)
Published 2026-08-19. Last modified 2026-09-09.