Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100667— grav-plugin-login 3.8.7 through 3.9.6 Two-Factor Authentication Bypass

Quick assessment

Affected
getgrav grav
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Grav CMS 的 Login 插件(grav-plugin-login)在版本 >= 3.8.7 且 < 3.9.7 中存在一个安全漏洞,允许绕过基于双重身份验证(2FA)的挑战机制。具体而言,当内容受 Twig 函数 或短代码 控制时,该漏洞可能导致 2FA 防护被绕过。 在启用了 2FA 的站点上, 方法仅检查会话中表明密码验证步骤已成功完成的标志,而未验证表示整个登录过程已彻底完成的标志。因此,处于 2FA 验证码输入提示阶段的会话仍被视为完全认证。攻击者即使仅掌握会员的密码而无法响应第二因素验证,仍可读

CVSS 5.3 · Medium EPSS 0.31% · P21
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100667

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
grav-plugin-login 3.8.7 through 3.9.6 Two-Factor Authentication Bypass
Source: CVE Program / CVE List V5
Vulnerability Description
grav-plugin-login (the Grav CMS Login plugin) versions >= 3.8.7 and < 3.9.7 allow the two-factor authentication challenge to be bypassed for content gated by the authenticated() Twig function or the [authenticated] shortcode. On sites with 2FA enabled, Login::isAuthenticated() checked only the session flag indicating that the password step had succeeded, not the flag indicating that login had completed, so a session sitting at the 2FA code prompt was treated as fully authenticated. An attacker who knows a member's password but cannot answer that member's second factor can therefore read member-only content rendered by the no-argument authenticated() or group authenticated(null, 'group') forms and by [authenticated]; the inverse [guest] shortcode is likewise evaluated too early. Impact is limited to disclosure of that content: the attacker does not obtain a completed session, cannot access pages protected by an access: rule, and cannot act as the user. The authenticated('some.permission') form, which goes through UserObject::authorize(), is not affected. Fixed in grav-plugin-login 3.9.7.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
认证中关键步骤缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
getgrav grav 3.8.7 ~ 3.9.7 -

II. Public POCs for CVE-2026-100667

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100667

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100667 (2)

Same Patch Batch · getgrav · 2026-09-26 · 7 CVEs total

CVE-2026-100670 8.8 HIGH Grav CMS 2.0.14 through 2.0.24 Privilege Escalation via Blueprint Guard Bypass
CVE-2026-100673 8.2 HIGH Grav Data Manager before 1.4.5 Stored XSS via item-detail view
CVE-2026-100671 8.0 HIGH Grav before 2.0.25 Session Cookie Theft via Twig Sandbox
CVE-2026-100669 7.5 HIGH Grav before 2.0.25 Sensitive File Disclosure via Case-Variation Bypass
CVE-2026-100672 7.5 HIGH grav-plugin-comments before 1.2.11 Unauthenticated Information Disclosure
CVE-2026-100668 6.5 MEDIUM Grav before 2.0.25 Sandbox Escape via array Filter

IV. Related Vulnerabilities

V. Comments for CVE-2026-100667

No comments yet


Leave a comment