What is CVE-2026-62669?
CVE-2026-62669 is a vulnerability in the Grav Login Plugin affecting versions prior to 3.8.11. The flaw in the `login.regenerate2FASecret` task fails to check the "authorized" status of a pending session, allowing an attacker who knows a victim's password to regenerate the 2FA secret. Affected users should immediately update the Grav Login Plugin to version 3.8.11 or higher.
Azərbaycanca: CVE-2026-62669 Grav Login Plugin-də aşkarlanmış zəiflikdir, versiya 3.8.11-dən əvvəlki sistemləri təsir edir. Bu boşluq `login.regenerate2FASecret` əməliyyatında "authorized" statusunun yoxlanılmaması səbəbindən, zərərçəkənin parolunu bilən hücumçuya 2FA sirrini yenidən yaratmağa imkan verir. Təsirə məruz qalan istifadəçilər dərhal Grav Login Plugin-i 3.8.11 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
What does an attacker need to know to exploit CVE-2026-62669?
The attacker needs to know the victim's password.
Which versions of the Grav Login Plugin are affected by this vulnerability?
Versions prior to 3.8.11 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.