CVE-2026-62232

HIGH

Grav < 2.0.4 2FA Bypass via Secret Regeneration

Title source: cna
STIX 2.1

Description

Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence, not authorization, during the pending TOTP challenge window. Attackers who know the victim's password can call this task without a CSRF nonce to overwrite the 2FA secret with an attacker-chosen value, compute a valid TOTP code, and complete authentication while reducing 2FA to password-only protection.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-7mgc-c7pq-3rr3)
https://github.com/getgrav/grav/security/advisories/GHSA-7mgc-c7pq-3rr3
Third Party Advisory third-party-advisory
VulnCheck Advisory: Grav < 2.0.4 2FA Bypass via Secret Regeneration
https://www.vulncheck.com/advisories/grav-2fa-bypass-via-secret-regeneration

Scores

CVSS v3 7.4
EPSS 0.0028
EPSS Percentile 20.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (2)
getgrav/grav < 2.0.4
getgrav/grav 2.0.4
Published Jul 17, 2026
Tracked Since Jul 17, 2026