Description
Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence, not authorization, during the pending TOTP challenge window. Attackers who know the victim's password can call this task without a CSRF nonce to overwrite the 2FA secret with an attacker-chosen value, compute a valid TOTP code, and complete authentication while reducing 2FA to password-only protection.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-7mgc-c7pq-3rr3)
https://github.com/getgrav/grav/security/advisories/GHSA-7mgc-c7pq-3rr3
Third Party Advisory third-party-advisory
VulnCheck Advisory: Grav < 2.0.4 2FA Bypass via Secret Regeneration
https://www.vulncheck.com/advisories/grav-2fa-bypass-via-secret-regeneration
Scores
CVSS v3
7.4
EPSS
0.0028
EPSS Percentile
20.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-862
Status
published
Products (2)
getgrav/grav
< 2.0.4
getgrav/grav
2.0.4
Published
Jul 17, 2026
Tracked Since
Jul 17, 2026