Grav Login Plugin Vulnerability Allows Two-Factor Authentication Bypass
A critical flaw in Grav versions before 2.0.4 permits attackers to bypass two-factor authentication by overwriting existing security secrets.
Grav versions prior to 2.0.4 are affected by a critical vulnerability, tracked as CVE-2026-62232, within the login plugin. The issue exists in the regenerate2FASecret task, which fails to verify user authorization during the pending TOTP challenge window, checking only for user existence.
An attacker who possesses a victim's password can exploit this flaw by calling the task without a CSRF nonce to overwrite the 2FA secret with a value of their choosing. This allows the attacker to generate a valid TOTP code and complete the authentication process, effectively reducing the security of the account to password-only protection.
Users of the Grav platform are advised to update to version 2.0.4 or later to address this vulnerability and restore proper two-factor authentication security.
Sources
- GitHub Security Advisories Original source
Continue Reading
FulcrumSec Claims Manchester Airport Breach, 86 GB Stolen
Extortion group FulcrumSec says it stole 86 GB from Manchester Airports Group, exposing detailed travel data.
Anthropic tackles Claude session hijacking via infostealers
Anthropic warns that infostealer malware is stealing Claude login sessions to drain accounts.
AI agents can be tricked into installing malware via unclaimed code packages
Researchers found 120 unregistered domains in AI documentation that could be hijacked to infect corporate networks.