THREAT OPS › Threat News › [GHSA] GHSA-7mgc-c7pq-3rr3 (high) — Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge
[GHSA] GHSA-7mgc-c7pq-3rr3 (high) — Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge
GHSA-7mgc-c7pq-3rr3 Severity: high CVE: CVE-2026-62669
Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge
### Summary When 2FA is enabled on an account, submitting correct credentials authenticates the user but leaves them unauthorized pending TOTP verification. During this pending-challenge window, the `login.regenerate2FASecret` task which requires only
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-62669cve
- http://127.0.0.1/grav/loginurl
- http://127.0.0.1/grav/login/task:login.regenerate2FASecreturl
- http://127.0.0.1/grav/url
- http://target/login/task:login.regenerate2FASecret`url
Original source: https://github.com/advisories/GHSA-7mgc-c7pq-3rr3