What is CVE-2026-66400?
A vulnerability in Grav Login Plugin versions prior to 3.8.13 allows insufficient session expiration for 'Remember Me' tokens due to improper timestamp validation in the findTriplet() method. This could enable attackers with a captured cookie to authenticate indefinitely instead of the configured duration. Users should upgrade to version 3.8.13 or later.
Azərbaycanca: Grav Login Plugin-in 3.8.13-dən əvvəlki versiyalarında 'Remember Me' tokenlərinin sessiya müddətinin düzgün yoxlanılmaması zəifliyi aşkarlanıb. Bu, ələ keçirilmiş 'Remember Me' çərəzini istifadə edən hücumçulara qeyri-məhdud müddət ərzində sistemə daxil olmaq imkanı yaradır. İstifadəçilərə plugin-i ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: shared vendor: Grav
FAQ2
Which versions of the Grav Login Plugin are affected by CVE-2026-66400?
All versions of the Grav Login Plugin prior to 3.8.13 are affected by this vulnerability.
What can an attacker achieve by exploiting CVE-2026-66400?
An attacker with a captured 'Remember Me' cookie can authenticate indefinitely instead of the configured duration.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.