CVE-2026-66400

MEDIUM

Grav Login Plugin before 3.8.13 Insufficient Session Expiration

Title source: cna
STIX 2.1

Description

Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php where the findTriplet() method fails to properly validate Remember Me token timestamps. Attackers with a captured Remember Me cookie can authenticate indefinitely instead of the configured timeout period, as the expiry check compares an array to a scalar value which always evaluates incorrectly in PHP.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-mj78-8gwc-vxjj)
https://github.com/getgrav/grav/security/advisories/GHSA-mj78-8gwc-vxjj
Third Party Advisory third-party-advisory
VulnCheck Advisory: Grav Login Plugin before 3.8.13 Insufficient Session Expiration
https://www.vulncheck.com/advisories/grav-login-plugin-before-insufficient-session-expiration

Scores

CVSS v3 4.8
EPSS 0.0015
EPSS Percentile 4.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-613
Status published
Products (2)
getgrav/grav < 3.8.13
getgrav/grav 3.8.13
Published Jul 29, 2026
Tracked Since Jul 29, 2026