CVE-2026-66400
Last modified
CVE-2026-66400 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php where the findTriplet() method fails to properly validate Remember Me token timestamps. Attackers with a captured Remember Me cookie can authenticate indefinitely instead of the configured timeout period, as the expiry check compares an array to a scalar value which always evaluates incorrectly in PHP.. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php where the findTriplet() method fails to properly validate Remember Me token timestamps. Attackers with a captured Remember Me cookie can authenticate indefinitely instead of the configured timeout period, as the expiry check compares an array to a scalar value which always evaluates incorrectly in PHP.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| getgrav | grav | < 3.8.13 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-66400?
How severe is CVE-2026-66400?
How do I fix CVE-2026-66400?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-66395SiYuan desktop before v3.7.2 contains a reflected cross-site…9.6
- CVE-2026-66396SiYuan before v3.7.2 fails to escape the title-img Individua…8.4
- CVE-2026-66397phpMyFAQ before 4.1.6 fails to validate path traversal seque…8.6
- CVE-2026-66398phpMyFAQ before v4.1.6 contains a remote code execution vuln…9.4
- CVE-2026-66399phpMyFAQ before 4.1.6 contains a privilege escalation vulner…8.5
- CVE-2026-6640The Media Library Assistant plugin for WordPress is vulnerab…6.4
- CVE-2026-66401FreeRDP before 3.29.0 contains an out-of-bounds heap read vu…2.1
- CVE-2026-66402FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains…9.8
- CVE-2026-66403DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for …7.5
- CVE-2026-66404DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server ce…6.5
- CVE-2026-66405DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers …8.8
- CVE-2026-66406DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with ser…4.8
Are you affected by CVE-2026-66400?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
