THREAT OPS › Threat News › [NVD] CVE-2026-72699 (MEDIUM 5.3) — The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register() method in classes/Login.php throws a distinct exception (EMAIL_NOT_AVAILABLE) when a submitted email address already belongs to an existing account, while all
[NVD] CVE-2026-72699 (MEDIUM 5.3) — The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register() method in classes/Login.php throws a distinct exception (EMAIL_NOT_AVAILABLE) when a submitted email address already belongs to an existing account, while all
CVE-2026-72699 CVSS: 5.3 MEDIUM Published: 2026-08-25T02:16:45.687
The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register() method in classes/Login.php throws a distinct exception (EMAIL_NOT_AVAILABLE) when a submitted email address already belongs to an existing account, while allowing registration to proceed otherwise. Because the
MITRE ATT&CK techniques
- Email AddressesT1589.002
Indicators of compromise
- CVE-2026-72699cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-72699