A vulnerability categorized as problematic has been discovered in getgrav grav up to 3.8.10. Affected is the function
regenerate2FASecret of the component Login. Such manipulation leads to cross-site request forgery.
This vulnerability is referenced as CVE-2026-62236. It is possible to launch the attack remotely. No exploit is available.