PT-2026-99338 · Grav · Grav-Plugin-Login

·

CVE-2026-100667

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions grav-plugin-login versions 3.8.7 through 3.9.6
Description A flaw exists where the two-factor authentication (2FA) challenge can be bypassed for content protected by the authenticated() Twig function or the [authenticated] shortcode. This occurs because the Login::isAuthenticated() function only verifies the session flag for successful password entry rather than confirming the entire login process is complete. Consequently, a session awaiting a 2FA code is incorrectly treated as fully authenticated. An attacker possessing a user's password can access member-only content rendered by the no-argument authenticated() form, the group authenticated(null, 'group') form, or the [authenticated] shortcode. Additionally, the [guest] shortcode is evaluated prematurely. The impact is limited to the disclosure of this specific content; the attacker cannot obtain a full session, access pages protected by an access: rule, or perform actions as the user. The authenticated('some.permission') form is not affected as it utilizes UserObject::authorize().
Recommendations Update grav-plugin-login to version 3.9.7.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100667

Affected Products

Grav-Plugin-Login