CVE-2026-66400 | getgrav Grav Login Plugin up to 3.8.12 Token Storage TokenStorage.php findTriplet session expiration

SecurityVulns

A vulnerability classified as critical was found in getgrav Grav Login Plugin up to 3.8.12. The impacted element is the function findTriplet of the file TokenStorage.php of the component Token Storage. Executing a manipulation can lead to session expiration.

This vulnerability is registered as CVE-2026-66400. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More