Summary
CVE-2026-72700 is a timing-based side-channel vulnerability (CWE-208: Observable Timing Discrepancy) affecting the login plugin bundled with the Grav flat-file CMS. The plugin validates password-reset and account-activation tokens using a non-constant-time === string comparison instead of hash_equals(), and the token-submission endpoint has no rate limiting. The issue carries a CVSS v4.0 base score of 8.7 (High), though the vendor and researcher both assess practical, remote exploitability as low.
Technical details
- Root cause: Token validation in
classes/Controller.php(taskReset()method) and in thelogin.phpaccount-activation handler compares submitted tokens to the expected value with PHP’s===operator rather than the constant-timehash_equals()function, which Grav already uses correctly elsewhere. - Trigger conditions: An attacker must repeatedly submit password-reset or account-activation tokens against the endpoint and statistically measure response timing to infer correct token characters.
- Attack vector: Network — no authentication or user interaction required to attempt exploitation, but the endpoint’s lack of rate limiting is what would allow the volume of timing samples needed for a practical attack.
- Impact: If successfully exploited, an attacker could recover a valid token and gain unauthorized password reset or account activation capability on a targeted account, potentially leading to account takeover. Researchers measured a 4.3% timing variance with
===versus 0.0% variance forhash_equals(), but note that network jitter typically obscures such small timing signals, and no working end-to-end network exploit has been publicly demonstrated.
Affected software
- Grav (login plugin component
getgrav/grav-plugin-login), all versions through 3.9.0
Severity
- CVSS v4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N - CVSS v3.1: 7.5 (High) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Upgrade Grav to version 3.9.1 or later, which replaces the vulnerable
===comparisons withhash_equals(). - If immediate patching is not possible: Restrict or monitor access to password-reset and account-activation endpoints, apply request rate limiting at the web server or WAF layer to prevent the high-volume repeated submissions a timing attack requires, and monitor logs for unusual bursts of reset/activation attempts against the same account.

