CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-62236

mediumCVSS 5.4covered by 1 sourcefirst seen 2026-07-17
grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASecret frontend task, which regenerates and persists a new TOTP secret for the authenticated session user without any anti-CSRF nonce or Origin/Referer check. Because Grav core dispatches the task from the GET 'task:' URI parameter and the default session cookie is SameSite=Lax, an attacker can lure a logged-in victim to an off-site page that performs a top-level GET navigation, rotating the victim's TOTP secret so their enrolled authenticator no longer matches the server, effectively forcing 2FA re-enrollment. Sites configured with session.samesite: Strict are not affected.

⚡ Watch CVE-2026-62236

Get an email if CVE-2026-62236 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-62236

CVE.org record

Embed the live status

CVE-2026-62236 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-62236 status](https://www.csirts.com/badge/CVE-2026-62236)](https://www.csirts.com/cve/CVE-2026-62236)