CVE-2026-66400: Grav Login Plugin before 3.8.13 Insufficient Session Expiration
Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php where the findTriplet() method fails to properly validate Remember Me token timestamps. Attackers with a captured Remember Me cookie can authenticate indefinitely instead of the configured timeout period, as the expiry check compares an array to a scalar value which always evaluates incorrectly in PHP.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Grav Login Pluginto a version that resolves this vulnerability.Fixed in 3.8.13
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66400?
CVE-2026-66400 has a medium severity rating of 4.8.
How do I fix CVE-2026-66400?
To fix CVE-2026-66400, upgrade the Grav Login Plugin to version 3.8.13 or later.
What does CVE-2026-66400 affect?
CVE-2026-66400 affects the Grav Login Plugin versions before 3.8.13.
What is the risk associated with CVE-2026-66400?
The risk associated with CVE-2026-66400 is considered medium due to insufficient session expiration allowing indefinite authentication.
What can attackers do with CVE-2026-66400?
Attackers can exploit CVE-2026-66400 by capturing a Remember Me cookie and authenticating indefinitely.