Grav · Grav-Plugin-Login · CVE-2026-100667
**Name of the Vulnerable Software and Affected Versions**
grav-plugin-login versions 3.8.7 through 3.9.6
**Description**
A flaw exists where the two-factor authentication (2FA) challenge can be bypassed for content protected by the `authenticated()` Twig function or the `[authenticated]` shortcode. This occurs because the `Login::isAuthenticated()` function only verifies the session flag for successful password entry rather than confirming the entire login process is complete. Consequently, a session awaiting a 2FA code is incorrectly treated as fully authenticated. An attacker possessing a user's password can access member-only content rendered by the no-argument `authenticated()` form, the group `authenticated(null, 'group')` form, or the `[authenticated]` shortcode. Additionally, the `[guest]` shortcode is evaluated prematurely. The impact is limited to the disclosure of this specific content; the attacker cannot obtain a full session, access pages protected by an `access:` rule, or perform actions as the user. The `authenticated('some.permission')` form is not affected as it utilizes `UserObject::authorize()`.
**Recommendations**
Update grav-plugin-login to version 3.9.7.