Junglewise Threat Intelligence

CVE-2026-62236: getgrav grav-plugin-login CSRF in regenerate2FASecret task

CVE-2026-62236 · Severity: medium · CVSS 5.4 · Published 2026-07-17

Technologies: Grav Login Plugin. Vendors: Grav, Getgrav.

Executive brief

The Login plugin for the Grav CMS contains a security flaw that allows an attacker to reset a user's two-factor authentication (2FA) settings. By tricking a logged-in user into clicking a malicious link, an attacker can force the system to generate a new security secret, making the user's existing authenticator app stop working. This results in a service disruption where the user must re-enroll their 2FA device to regain full access to their account.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the 'login.regenerate2FASecret' frontend task of the Grav Login plugin. The application fails to implement anti-CSRF nonces or Origin/Referer checks for this specific task. Because Grav dispatches tasks via GET parameters and uses 'SameSite=Lax' for session cookies by default, an attacker can trigger the secret regeneration via a top-level GET navigation (e.g., a malicious link). This overwrites the 'twofa_secret' in the user's account file, desynchronizing their authenticator app from the server. The vulnerability is patched in version 3.8.11; sites using 'session.samesite: Strict' are not affected.

Affected products

  • getgrav grav-plugin-login < 3.8.11

Timeline

  • 2026-06-29: advisory: GitHub Security Advisory published
  • 2026-07-17: disclosed: NVD publication date

References

Related threats