What is CVE-2026-62671?
This vulnerability in the Grav Login Plugin (prior to version 3.8.11) allows the `regenerate2FASecret` task to be called via a GET request without requiring a login-form nonce, Origin, or Referer check. This could enable an unauthenticated user to regenerate the Two-Factor Authentication (2FA) secret. Users should immediately upgrade the plugin to the latest version.
Azərbaycanca: CVE-2026-62671, Grav Login Plugin-da aşkar edilmiş zəiflikdir. 3.8.11 versiyasından əvvəl, təhlükəsizlik tokeni (nonce) olmadan `regenerate2FASecret` endpointinə edilən sorğular qəbul edilir. Bu, autentifikasiya olunmamış istifadəçilərə ikifaktorlu autentifikasiya (2FA) parametrlərini sıfırlamağa imkan yaradır. Plugin-i təcili olaraq ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
What versions of the Grav Login Plugin are affected by CVE-2026-62671?
All versions prior to 3.8.11 are affected.
What can an unauthenticated user do by exploiting CVE-2026-62671?
The vulnerability allows an unauthenticated user to regenerate the Two-Factor Authentication (2FA) secret via the `regenerate2FASecret` endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.