---
id: CVE-2026-62232
title: >-
  Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in
  the login plugin where the regenerate2FASecret task checks only user
  existence, not authorization, during the pending TOTP challenge window
summary: >-
  Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in
  the login plugin where the regenerate2FASecret task checks only user
  existence, not authorization, during the pending TOTP challenge window.
  Attackers who kno…
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-862
vendor: getgrav
product: grav
affected:
  - grav < 2.0.4
published: '2026-07-17'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:26.933'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-62232'
references:
  - url: 'https://github.com/getgrav/grav/security/advisories/GHSA-7mgc-c7pq-3rr3'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/grav-2fa-bypass-via-secret-regeneration
    label: disclosure@vulncheck.com
  - url: 'https://github.com/getgrav/grav/security/advisories/GHSA-7mgc-c7pq-3rr3'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-07-17T10:29:05.336188Z'
epss: 0.00453
epssPercentile: 0.37311
ingestedAt: '2026-10-08T16:52:14.702Z'
---

## Overview

Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence, not authorization, during the pending TOTP challenge window. Attackers who know the victim's password can call this task without a CSRF nonce to overwrite the 2FA secret with an attacker-chosen value, compute a valid TOTP code, and complete authentication while reducing 2FA to password-only protection.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
