CVE-2026-66400
MEDIUMGrav Login Plugin before 3.8.13 Insufficient Session Expiration
Title source: cnaDescription
Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php where the findTriplet() method fails to properly validate Remember Me token timestamps. Attackers with a captured Remember Me cookie can authenticate indefinitely instead of the configured timeout period, as the expiry check compares an array to a scalar value which always evaluates incorrectly in PHP.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-mj78-8gwc-vxjj)
https://github.com/getgrav/grav/security/advisories/GHSA-mj78-8gwc-vxjj
Third Party Advisory third-party-advisory
VulnCheck Advisory: Grav Login Plugin before 3.8.13 Insufficient Session Expiration
https://www.vulncheck.com/advisories/grav-login-plugin-before-insufficient-session-expiration
Scores
CVSS v3
4.8
EPSS
0.0015
EPSS Percentile
4.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-613
Status
published
Products (2)
getgrav/grav
< 3.8.13
getgrav/grav
3.8.13
Published
Jul 29, 2026
Tracked Since
Jul 29, 2026