THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-7mgc-c7pq-3rr3 (high) — Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge

[GHSA] GHSA-7mgc-c7pq-3rr3 (high) — Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge

highgithub_advisoriesPublished 2026-09-02

GHSA-7mgc-c7pq-3rr3 Severity: high CVE: CVE-2026-62669

Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge

### Summary When 2FA is enabled on an account, submitting correct credentials authenticates the user but leaves them unauthorized pending TOTP verification. During this pending-challenge window, the `login.regenerate2FASecret` task which requires only

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-7mgc-c7pq-3rr3