Two-Factor Authentication Bypass in Grav by Getgrav
CVE-2026-62232
9.1CRITICAL
What is CVE-2026-62232?
Grav prior to version 2.0.4 has a security flaw in its login plugin that allows an attacker to bypass two-factor authentication (2FA). This occurs when the regenerate2FASecret task only verifies the existence of a user without checking for proper authorization during the pending TOTP challenge window. If an attacker knows the victim's password, they can exploit this vulnerability to overwrite the victim's 2FA secret with a value of their choosing. Consequently, the attacker can generate a valid TOTP code, completing the authentication process and effectively reducing the 2FA security measure to a mere password-based defense.
Affected Version(s)
grav 0 < 2.0.4
grav 2.0.4
