CWE-294
AllowedAuthentication Bypass by Capture-replay
Abstraction: Base · Status: Incomplete
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
440 vulnerabilities reference this CWE, most recent first.
CVE-2026-103655 (GCVE-0-2026-103655)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:08 – Updated: 2026-10-01 15:25- CWE-294 - Authentication Bypass via Logical Flaw
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/a020fa47b | patch |
qwen3.8:27b
1 event
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-01 07:52 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/a020fa47b.patch
6fce2d1f789e… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
a020fa47b6c3
|
fix: [security] Refuse a TOTP code that was already used to | 6fce2d1f789e… |
Fix summary
The fix introduces a single-use enforcement mechanism for TOTP codes. Upon successful verification, the system records the TOTP period step in a Redis key scoped to the user and step number, using a SET-NX (set-if-not-exists) operation with a TTL of three times the TOTP period. Any subsequent attempt to authenticate with a code from the same period will fail the SET-NX check and be rejected, effectively making each TOTP code single-use within its validity window.
Patch summary
In app/Controller/UsersController.php, the otp() method was modified to capture the current timestamp and pass it to the TOTP verify call. A new private method __claimTotpStep() was added, which computes the TOTP step (intdiv of elapsed time over period), constructs a Redis key of the form misp:otp:totp_used:{userId}:{step}, and attempts a SET with NX and EX (3x period) flags via RedisTool. The login proceeds only if both the TOTP verification and the claim succeed. Thirteen lines added, one line modified.
CVSS rationale
AV:N: the TOTP code is transmitted over the network during login. AC:H: exploitation requires the attacker to intercept a valid TOTP code during a legitimate login and replay it within the short validity window (typically 30 s), which is a non-trivial timing and positioning requirement. AT:N: no manipulation of the target system is needed. PR:N: the attacker is unauthenticated. UI:N: no user interaction beyond the victim's normal login is required. VC:H / VI:H: successful exploitation grants full access to the targeted user's account, including threat-intelligence data and administrative capabilities. VA:L: the attacker could disrupt services by modifying or deleting data. SC/SI/SA:N: no impact on secondary systems is evidenced.
Weakness rationale
- CWE-294 The TOTP verification logic accepted the same code multiple times within its validity period because no state was tracked to mark a period as consumed. This is a logical flaw in the authentication mechanism that permits replay of a valid one-time credential, fitting CWE-294 more precisely than the broader CWE-287.
Attack pattern rationale
- CAPEC-122 The closest available CAPEC pattern is Session Hijacking, as the attacker gains unauthorized access to a user's authenticated session by replaying a captured credential (the TOTP code). The mapping is imperfect because the attack targets a one-time authentication token rather than a persistent session identifier, and the window is very short (one TOTP period). No CAPEC specifically covers one-time-code replay, so CAPEC-122 is the best available match.
Assumptions to verify
- The affected version range is inferred from the tag_version_boundary (v2.5.48, 40 commits after fix); the exact first affected version is not stated in the patch metadata and is recorded as unspecified.
- The TOTP validity period is assumed to be the standard 30 seconds based on the OTPHP library default; the patch does not hard-code a specific period value.
- The CAPEC-122 mapping is the closest available pattern; no CAPEC specifically addresses one-time-code replay, so the mapping carries uncertainty.
- CVSS AC is rated High because exploitation requires intercepting a valid TOTP code during a live login and replaying it within a short time window; if the attacker already possesses the code (e.g., via a compromised client), complexity would be lower.
- The Redis dependency for the fix is assumed to be available in the deployment; if Redis is unavailable, the fix's behavior is not specified in the patch.
- The Co-Authored-By line references an AI tool (Claude Opus 5.5); it is credited as a tool rather than a human remediation developer.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 11 | medium | 6 |
- 2026-09-23 14:24 UTC Fix developed Corrective change authored (a020fa47b6c3cb5b43d841afe2ccf149889fad6b): fix: [security] Refuse a TOTP code that was already used to https://github.com/MISP/MISP/commit/a020fa47b.patch
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103655",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:25:45.460434Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:25:55.269Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"app/Controller/UsersController.php (otp method)"
],
"product": "MISP",
"programFiles": [
"app/Controller/UsersController.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Tanguy Snoeck of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window.\u003c/p\u003e\u003cp\u003eThe issue exists in the user login flow where a TOTP code is verified as a second authentication factor. Because the system did not record whether a given TOTP period had already been consumed, the same code remained valid for its entire time window (typically 30 seconds). An attacker who captures a legitimate code during a user\u0027s login could replay it to authenticate a second session as that user.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- The target user has TOTP-based two-factor authentication enabled.\u003c/p\u003e\u003cp\u003e- The attacker is in a position to observe or intercept the TOTP code during a legitimate login (e.g., network-level interception, shoulder surfing, or a compromised client).\u003c/p\u003e\u003cp\u003e- The replay must occur within the TOTP validity period.\u003c/p\u003e\u003cp\u003eSecurity impact:\u003c/p\u003e\u003cp\u003e- Unauthorized account access by replaying a captured one-time code.\u003c/p\u003e\u003cp\u003e- Potential compromise of threat-intelligence data and administrative functions accessible to the targeted user.\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt;v2.5.48.\u003c/p\u003e"
}
],
"value": "MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window.\n\nThe issue exists in the user login flow where a TOTP code is verified as a second authentication factor. Because the system did not record whether a given TOTP period had already been consumed, the same code remained valid for its entire time window (typically 30 seconds). An attacker who captures a legitimate code during a user\u0027s login could replay it to authenticate a second session as that user.\n\nPreconditions:\n\n- The target user has TOTP-based two-factor authentication enabled.\n\n- The attacker is in a position to observe or intercept the TOTP code during a legitimate login (e.g., network-level interception, shoulder surfing, or a compromised client).\n\n- The replay must occur within the TOTP validity period.\n\nSecurity impact:\n\n- Unauthorized account access by replaying a captured one-time code.\n\n- Potential compromise of threat-intelligence data and administrative functions accessible to the targeted user.\n\nAffected versions: \u003cv2.5.48."
}
],
"impacts": [
{
"capecId": "CAPEC-122",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-122 Session Hijacking"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T07:52:43Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-294",
"description": "CWE-294 Authentication Bypass via Logical Flaw",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:08:55.013Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/a020fa47b"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix introduces a single-use enforcement mechanism for TOTP codes. Upon successful verification, the system records the TOTP period step in a Redis key scoped to the user and step number, using a SET-NX (set-if-not-exists) operation with a TTL of three times the TOTP period. Any subsequent attempt to authenticate with a code from the same period will fail the SET-NX check and be rejected, effectively making each TOTP code single-use within its validity window.\u003c/p\u003e"
}
],
"value": "The fix introduces a single-use enforcement mechanism for TOTP codes. Upon successful verification, the system records the TOTP period step in a Redis key scoped to the user and step number, using a SET-NX (set-if-not-exists) operation with a TTL of three times the TOTP period. Any subsequent attempt to authenticate with a code from the same period will fail the SET-NX check and be rejected, effectively making each TOTP code single-use within its validity window."
}
],
"title": "MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version range is inferred from the tag_version_boundary (v2.5.48, 40 commits after fix); the exact first affected version is not stated in the patch metadata and is recorded as unspecified.",
"The TOTP validity period is assumed to be the standard 30 seconds based on the OTPHP library default; the patch does not hard-code a specific period value.",
"The CAPEC-122 mapping is the closest available pattern; no CAPEC specifically addresses one-time-code replay, so the mapping carries uncertainty.",
"CVSS AC is rated High because exploitation requires intercepting a valid TOTP code during a live login and replaying it within a short time window; if the attacker already possesses the code (e.g., via a compromised client), complexity would be lower.",
"The Redis dependency for the fix is assumed to be available in the deployment; if Redis is unavailable, the fix\u0027s behavior is not specified in the patch.",
"The Co-Authored-By line references an AI tool (Claude Opus 5.5); it is credited as a tool rather than a human remediation developer."
],
"capecRationale": [
{
"capecId": "CAPEC-122",
"rationale": "The closest available CAPEC pattern is Session Hijacking, as the attacker gains unauthorized access to a user\u0027s authenticated session by replaying a captured credential (the TOTP code). The mapping is imperfect because the attack targets a one-time authentication token rather than a persistent session identifier, and the window is very short (one TOTP period). No CAPEC specifically covers one-time-code replay, so CAPEC-122 is the best available match."
}
],
"commit": "a020fa47b6c3cb5b43d841afe2ccf149889fad6b",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Tanguy Snoeck of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N: the TOTP code is transmitted over the network during login. AC:H: exploitation requires the attacker to intercept a valid TOTP code during a legitimate login and replay it within the short validity window (typically 30 s), which is a non-trivial timing and positioning requirement. AT:N: no manipulation of the target system is needed. PR:N: the attacker is unauthenticated. UI:N: no user interaction beyond the victim\u0027s normal login is required. VC:H / VI:H: successful exploitation grants full access to the targeted user\u0027s account, including threat-intelligence data and administrative capabilities. VA:L: the attacker could disrupt services by modifying or deleting data. SC/SI/SA:N: no impact on secondary systems is evidenced.",
"fixSummary": "The fix introduces a single-use enforcement mechanism for TOTP codes. Upon successful verification, the system records the TOTP period step in a Redis key scoped to the user and step number, using a SET-NX (set-if-not-exists) operation with a TTL of three times the TOTP period. Any subsequent attempt to authenticate with a code from the same period will fail the SET-NX check and be rejected, effectively making each TOTP code single-use within its validity window.",
"generatedAt": "2026-10-01T07:52:44.000034Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 6,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "6fce2d1f789e3b4c0cbb7b4d81079334f66f1707bb5422f49915393cab88143f",
"patchSummary": "In app/Controller/UsersController.php, the otp() method was modified to capture the current timestamp and pass it to the TOTP verify call. A new private method __claimTotpStep() was added, which computes the TOTP step (intdiv of elapsed time over period), constructs a Redis key of the form misp:otp:totp_used:{userId}:{step}, and attempts a SET with NX and EX (3x period) flags via RedisTool. The login proceeds only if both the TOTP verification and the claim succeed. Thirteen lines added, one line modified.",
"patchTruncated": false,
"patches": [
{
"commit": "a020fa47b6c3cb5b43d841afe2ccf149889fad6b",
"date": "Wed, 23 Sep 2026 16:24:44 +0200",
"patchSha256": "6fce2d1f789e3b4c0cbb7b4d81079334f66f1707bb5422f49915393cab88143f",
"source": "https://github.com/MISP/MISP/commit/a020fa47b.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/a020fa47b.patch",
"subject": "fix: [security] Refuse a TOTP code that was already used to"
}
],
"source": "https://github.com/MISP/MISP/commit/a020fa47b.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T07:52:44Z",
"version": "2.0.3"
},
"subject": "fix: [security] Refuse a TOTP code that was already used to",
"tagVersionBoundary": {
"commits_after_fix": 40,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-294",
"rationale": "The TOTP verification logic accepted the same code multiple times within its validity period because no state was tracked to mark a period as consumed. This is a logical flaw in the authentication mechanism that permits replay of a valid one-time credential, fitting CWE-294 more precisely than the broader CWE-287."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (a020fa47b6c3cb5b43d841afe2ccf149889fad6b): fix: [security] Refuse a TOTP code that was already used to",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/a020fa47b.patch"
],
"timestamp": "2026-09-23T14:24:44Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20194"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103655",
"datePublished": "2026-10-01T08:08:55.013Z",
"dateReserved": "2026-10-01T08:08:52.909Z",
"dateUpdated": "2026-10-01T15:25:55.269Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100834 (GCVE-0-2026-100834)
Vulnerability from cvelistv5 – Published: 2026-09-27 01:28 – Updated: 2026-09-30 17:03- CWE-294 - Authentication Bypass by Capture-replay
| URL | Tags |
|---|---|
| https://github.com/http4k/http4k/security/advisor… | vendor-advisory |
| https://github.com/http4k/http4k/commit/8a52b615b1 | patch |
| https://github.com/http4k/http4k/commit/4f904b4692 | patch |
| https://www.vulncheck.com/advisories/http4k-befor… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100834",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T17:03:50.406355Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T17:03:58.285Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:maven/org.http4k/http4k-security-digest",
"product": "http4k",
"vendor": "http4k",
"versions": [
{
"lessThan": "6.48.0.0",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "6.48.0.0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:maven/org.http4k/http4k-security-digest",
"product": "http4k",
"vendor": "http4k",
"versions": [
{
"lessThan": "5.42.0.0",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "5.42.0.0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:maven/org.http4k/http4k-security-digest",
"product": "http4k",
"vendor": "http4k",
"versions": [
{
"lessThan": "4.51.0.0",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "4.51.0.0",
"versionType": "custom"
}
]
}
],
"datePublic": "2026-06-16T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "http4k\u0027s Digest authentication module (org.http4k:http4k-security-digest) before versions 6.48.0.0, 5.42.0.0 and 4.51.0.0 defaults the nonceVerifier parameter of ServerFilters.DigestAuth and DigestAuthProvider to { true }, so every nonce is accepted regardless of its value, age, or prior use. Applications relying on this default have no replay protection on Digest authentication: an attacker who can capture a valid \u0027Authorization: Digest\u0027 response (for example by observing network traffic or reading logs) can replay it indefinitely against the same protected resource."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-294",
"description": "Authentication Bypass by Capture-replay",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-27T01:28:32.781Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-c7jm-38gq-h67h)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/http4k/http4k/security/advisories/GHSA-c7jm-38gq-h67h"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/http4k/http4k/commit/8a52b615b1"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/http4k/http4k/commit/4f904b4692"
},
{
"name": "VulnCheck Advisory: http4k before 6.48.0.0 Digest Authentication Replay Protection Bypass",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/http4k-before-6.48.0.0-digest-authentication-replay-protection-bypass"
}
],
"title": "http4k before 6.48.0.0 Digest Authentication Replay Protection Bypass",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-100834",
"datePublished": "2026-09-27T01:28:32.781Z",
"dateReserved": "2026-09-26T23:23:03.410Z",
"dateUpdated": "2026-09-30T17:03:58.285Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-94112 (GCVE-0-2026-94112)
Vulnerability from cvelistv5 – Published: 2026-09-20 11:56 – Updated: 2026-09-21 20:46- CWE-294 - Authentication Bypass by Capture-replay
| URL | Tags |
|---|---|
| https://github.com/mayswind/ezbookkeeping/securit… | vendor-advisory |
| https://github.com/mayswind/ezbookkeeping/commit/… | patch |
| https://github.com/mayswind/ezbookkeeping/release… | release-notes |
| https://www.vulncheck.com/advisories/mayswind-ezb… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| mayswind | ezBookkeeping |
Affected:
0 , < 2.0.0
(semver)
cpe:2.3:a:mayswind:ezbookkeeping:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-94112",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-21T16:23:05.246566Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T20:46:39.064Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:golang/github.com/mayswind/ezbookkeeping",
"product": "ezBookkeeping",
"repo": "https://github.com/mayswind/ezbookkeeping",
"vendor": "mayswind",
"versions": [
{
"lessThan": "2.0.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mayswind:ezbookkeeping:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Waleed Hassan (GhostOverflow)"
}
],
"datePublic": "2026-09-16T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window. Attackers with stolen credentials can authenticate and reuse a captured passcode against multiple authorization attempts for approximately 90 seconds without detection."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-294",
"description": "Authentication Bypass by Capture-replay",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-20T11:56:07.691Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-p6qr-48g6-97q3)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/mayswind/ezbookkeeping/security/advisories/GHSA-p6qr-48g6-97q3"
},
{
"tags": [
"patch"
],
"url": "https://github.com/mayswind/ezbookkeeping/commit/3dd6286d7a3ab0f980a6d36339b9c9c4df9467e4"
},
{
"name": "ezBookkeeping v2.0.0 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/mayswind/ezbookkeeping/releases/tag/v2.0.0"
},
{
"name": "VulnCheck Advisory: mayswind ezBookkeeping before 2.0.0 TOTP Replay Attack",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/mayswind-ezbookkeeping-before-2.0.0-totp-replay-attack"
}
],
"title": "mayswind ezBookkeeping before 2.0.0 TOTP Replay Attack",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-94112",
"datePublished": "2026-09-20T11:56:07.691Z",
"dateReserved": "2026-09-20T11:41:36.494Z",
"dateUpdated": "2026-09-21T20:46:39.064Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-90997 (GCVE-0-2026-90997)
Vulnerability from cvelistv5 – Published: 2026-09-17 18:47 – Updated: 2026-09-25 06:42- CWE-294 - Authentication Bypass by Capture-replay
| URL | Tags |
|---|---|
| https://access.redhat.com/security/cve/CVE-2026-90997 | vdb-entryx_refsource_REDHAT |
| https://bugzilla.redhat.com/show_bug.cgi?id=2533141 | issue-trackingx_refsource_REDHAT |
| Vendor | Product | Version | |
|---|---|---|---|
| Keycloak | Keycloak |
Affected:
26.7.0 , < 26.7.4
(semver)
|
|
| Red Hat | Red Hat Build of Keycloak |
cpe:/a:redhat:build_keycloak:
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-90997",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-21T21:07:40.908040Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T21:07:53.300Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://github.com/keycloak/keycloak",
"defaultStatus": "unaffected",
"packageName": "keycloak-services",
"product": "Keycloak",
"vendor": "Keycloak",
"versions": [
{
"lessThan": "26.7.4",
"status": "affected",
"version": "26.7.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:build_keycloak:"
],
"defaultStatus": "unaffected",
"packageName": "rhbk/keycloak-rhel9",
"product": "Red Hat Build of Keycloak",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:build_keycloak:"
],
"defaultStatus": "unaffected",
"packageName": "rhbk/keycloak-rhel9-operator",
"product": "Red Hat Build of Keycloak",
"vendor": "Red Hat"
}
],
"credits": [
{
"lang": "en",
"value": "Red Hat would like to thank Bruno Oliveira of IBM in collaboration with OpenAI for reporting this issue."
}
],
"datePublic": "2026-09-16T14:21:23.000Z",
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak\u0027s application logic allows an attacker to bypass replay protection. This vulnerability enables an attacker who intercepts single-use security artifacts, such as JWT client assertions, DPoP proofs, or one-time password (TOTP) codes, to replay them. Successful exploitation grants unauthorized access to the token endpoint or login flow."
}
],
"metrics": [
{
"other": {
"content": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"value": "Important"
},
"type": "Red Hat severity rating"
}
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-294",
"description": "Authentication Bypass by Capture-replay",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T06:42:50.534Z",
"orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
"shortName": "redhat"
},
"references": [
{
"tags": [
"vdb-entry",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/security/cve/CVE-2026-90997"
},
{
"name": "RHBZ#2533141",
"tags": [
"issue-tracking",
"x_refsource_REDHAT"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533141"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-14T14:53:20.409Z",
"value": "Reported to Red Hat."
},
{
"lang": "en",
"time": "2026-09-16T14:21:23.000Z",
"value": "Made public."
}
],
"title": "Keycloak-services: keycloak: replay protection bypass leads to unauthorized access via database driver semantics mismatch",
"workarounds": [
{
"lang": "en",
"value": "To mitigate this issue, configure the JDBC connection string for MySQL/MariaDB to explicitly set `useAffectedRows=true`. This ensures the database driver correctly reports affected rows, preventing the replay protection bypass. This mitigation is applicable only when Keycloak is deployed in stateless mode and utilizes MySQL or MariaDB as its database. A restart of the Keycloak service will be required for the configuration change to take effect."
}
],
"x_generator": {
"engine": "cvelib 1.8.0"
},
"x_redhatCweChain": "CWE-294: Authentication Bypass by Capture-replay"
}
},
"cveMetadata": {
"assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
"assignerShortName": "redhat",
"cveId": "CVE-2026-90997",
"datePublished": "2026-09-17T18:47:34.059Z",
"dateReserved": "2026-09-14T14:53:37.815Z",
"dateUpdated": "2026-09-25T06:42:50.534Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-88278 (GCVE-0-2026-88278)
Vulnerability from cvelistv5 – Published: 2026-09-10 08:21 – Updated: 2026-09-10 15:30- CWE-294 - Authentication bypass by capture-replay
| Vendor | Product | Version | |
|---|---|---|---|
| GeoVision Inc. | GV-LPCLPC2011/2211 |
Affected:
1.13
Unaffected: 1.14 cpe:2.3:a:geovision_inc.:gv-lpclpc2011_2211:1.13:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-88278",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-10T15:26:12.690610Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T15:30:12.089Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "GV-LPCLPC2011/2211",
"vendor": "GeoVision Inc.",
"versions": [
{
"status": "affected",
"version": "1.13"
},
{
"status": "unaffected",
"version": "1.14"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:geovision_inc.:gv-lpclpc2011_2211:1.13:*:*:*:*:*:*:*",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:geovision_inc.:gv-lpclpc2011_2211:1.14:*:*:*:*:*:*:*",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
}
],
"datePublic": "2026-09-10T03:56:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations."
}
],
"value": "GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations."
}
],
"impacts": [
{
"capecId": "CAPEC-60",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-60 Reusing Session IDs (aka Session Replay)"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-294",
"description": "CWE-294 Authentication bypass by capture-replay",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T08:21:58.700Z",
"orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
"shortName": "GV"
},
"references": [
{
"url": "https://www.geovision.com.tw/cyber_security.php"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "GV-LPCLPC2011/2211 - ONVIF WS-Security PasswordDigest Replay",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
"assignerShortName": "GV",
"cveId": "CVE-2026-88278",
"datePublished": "2026-09-10T08:21:58.700Z",
"dateReserved": "2026-09-10T02:56:04.082Z",
"dateUpdated": "2026-09-10T15:30:12.089Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-87119 (GCVE-0-2026-87119)
Vulnerability from cvelistv5 – Published: 2026-09-22 11:16 – Updated: 2026-09-22 12:02- CWE-294 - Authentication Bypass by Capture-replay
| URL | Tags |
|---|---|
| https://github.com/ZenHive/mpp/security/advisorie… | relatedvendor-advisory |
| https://cna.erlef.org/cves/CVE-2026-87119.html | related |
| https://osv.dev/vulnerability/EEF-CVE-2026-87119 | related |
| https://github.com/ZenHive/mpp/commit/db464dfa9a8… | related |
| https://github.com/ZenHive/mpp/commit/4b6eaec02af… | patch |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-87119",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T12:02:12.184296Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T12:02:31.484Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://repo.hex.pm",
"cpes": [
"cpe:2.3:a:ZenHive:mpp:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"modules": [
"\u0027Elixir.MPP.Methods.Tempo.KeyAuthorization\u0027",
"\u0027Elixir.MPP.Methods.Tempo.Subscription\u0027"
],
"packageName": "mpp",
"packageURL": "pkg:hex/mpp",
"product": "mpp",
"programFiles": [
"lib/mpp/methods/tempo/key_authorization.ex",
"lib/mpp/methods/tempo/subscription.ex"
],
"programRoutines": [
{
"name": "\u0027Elixir.MPP.Methods.Tempo.KeyAuthorization\u0027:verify/3"
},
{
"name": "\u0027Elixir.MPP.Methods.Tempo.KeyAuthorization\u0027:wallet_params/2"
},
{
"name": "\u0027Elixir.MPP.Methods.Tempo.KeyAuthorization\u0027:from_rpc/1"
},
{
"name": "\u0027Elixir.MPP.Methods.Tempo.Subscription\u0027:verify/2"
}
],
"repo": "https://github.com/ZenHive/mpp",
"vendor": "ZenHive",
"versions": [
{
"lessThan": "0.16.2",
"status": "affected",
"version": "0.14.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://github.com",
"cpes": [
"cpe:2.3:a:ZenHive:mpp:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"modules": [
"\u0027Elixir.MPP.Methods.Tempo.KeyAuthorization\u0027",
"\u0027Elixir.MPP.Methods.Tempo.Subscription\u0027"
],
"packageName": "zenhive/mpp",
"packageURL": "pkg:github/zenhive/mpp",
"product": "mpp",
"programFiles": [
"lib/mpp/methods/tempo/key_authorization.ex",
"lib/mpp/methods/tempo/subscription.ex"
],
"programRoutines": [
{
"name": "\u0027Elixir.MPP.Methods.Tempo.KeyAuthorization\u0027:verify/3"
},
{
"name": "\u0027Elixir.MPP.Methods.Tempo.KeyAuthorization\u0027:wallet_params/2"
},
{
"name": "\u0027Elixir.MPP.Methods.Tempo.KeyAuthorization\u0027:from_rpc/1"
},
{
"name": "\u0027Elixir.MPP.Methods.Tempo.Subscription\u0027:verify/2"
}
],
"repo": "https://github.com/ZenHive/mpp",
"vendor": "ZenHive",
"versions": [
{
"lessThan": "4b6eaec02af0e8485cfb4ff68f467d075ed5dd6f",
"status": "affected",
"version": "db464dfa9a86ccda58f0827101f6da6bd8aafa78",
"versionType": "git"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eOnly deployments offering Tempo subscriptions are affected, which requires \u003ccode\u003esubscription_access_key_private_key\u003c/code\u003e in the Tempo \u003ccode\u003emethod_config\u003c/code\u003e. Exploitation further requires the attacker to have obtained a payer\u0027s signed activation credential, in transit over a hop that is not TLS-protected or at rest in a log, an intermediary, or a client retry buffer.\u003c/p\u003e"
},
{
"base64": false,
"type": "text/markdown",
"value": "Only deployments offering Tempo subscriptions are affected, which requires `subscription_access_key_private_key` in the Tempo `method_config`. Exploitation further requires the attacker to have obtained a payer\u0027s signed activation credential, in transit over a hop that is not TLS-protected or at rest in a log, an intermediary, or a client retry buffer."
}
],
"value": "Only deployments offering Tempo subscriptions are affected, which requires subscription_access_key_private_key in the Tempo method_config. Exploitation further requires the attacker to have obtained a payer\u0027s signed activation credential, in transit over a hop that is not TLS-protected or at rest in a log, an intermediary, or a client retry buffer."
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ZenHive:mpp:*:*:*:*:*:*:*:*",
"versionEndExcluding": "0.16.2",
"versionStartIncluding": "0.14.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "E.FU"
},
{
"lang": "en",
"type": "remediation developer",
"value": "E.FU"
},
{
"lang": "en",
"type": "coordinator",
"value": "Jonatan M\u00e4nnchen / EEF"
}
],
"dateAssigned": "2026-09-15T15:20:31.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAuthentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly.\u003c/p\u003e\n\u003cp\u003eThe payer signs a Tempo \u003ccode\u003eKeyAuthorization\u003c/code\u003e over the chain id, key type, key id, expiry, limits and scopes only, with nothing tying it to the challenge that prompted it. \u003ccode\u003eMPP.Methods.Tempo.KeyAuthorization.verify/3\u003c/code\u003e in \u003ccode\u003elib/mpp/methods/tempo/key_authorization.ex\u003c/code\u003e pins each of those signed fields against the subscription request, and the access key it pins is a static per-endpoint server key, so one signed authorization verifies against every challenge the server issues for the same subscription terms. \u003ccode\u003eMPP.Methods.Tempo.Subscription.activate/4\u003c/code\u003e deduplicates activations by challenge id, so presenting the captured credential under a fresh challenge produces a different dedup key, \u003ccode\u003eclaim_activation\u003c/code\u003e succeeds, and the subscription transaction is built and broadcast again. Each replay charges the payer\u0027s wallet a new first-period settlement and re-authorizes the server key, bounded only by the subscription expiry and the chain\u0027s own semantics for re-installing an existing key.\u003c/p\u003e\n\u003cp\u003eThis issue affects mpp: from 0.14.0 before 0.16.2.\u003c/p\u003e"
},
{
"base64": false,
"type": "text/markdown",
"value": "Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly.\n\nThe payer signs a Tempo `KeyAuthorization` over the chain id, key type, key id, expiry, limits and scopes only, with nothing tying it to the challenge that prompted it. `MPP.Methods.Tempo.KeyAuthorization.verify/3` in `lib/mpp/methods/tempo/key_authorization.ex` pins each of those signed fields against the subscription request, and the access key it pins is a static per-endpoint server key, so one signed authorization verifies against every challenge the server issues for the same subscription terms. `MPP.Methods.Tempo.Subscription.activate/4` deduplicates activations by challenge id, so presenting the captured credential under a fresh challenge produces a different dedup key, `claim_activation` succeeds, and the subscription transaction is built and broadcast again. Each replay charges the payer\u0027s wallet a new first-period settlement and re-authorizes the server key, bounded only by the subscription expiry and the chain\u0027s own semantics for re-installing an existing key.\n\nThis issue affects mpp: from 0.14.0 before 0.16.2."
}
],
"value": "Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly.\n\nThe payer signs a Tempo KeyAuthorization over the chain id, key type, key id, expiry, limits and scopes only, with nothing tying it to the challenge that prompted it. MPP.Methods.Tempo.KeyAuthorization.verify/3 in lib/mpp/methods/tempo/key_authorization.ex pins each of those signed fields against the subscription request, and the access key it pins is a static per-endpoint server key, so one signed authorization verifies against every challenge the server issues for the same subscription terms. MPP.Methods.Tempo.Subscription.activate/4 deduplicates activations by challenge id, so presenting the captured credential under a fresh challenge produces a different dedup key, claim_activation succeeds, and the subscription transaction is built and broadcast again. Each replay charges the payer\u0027s wallet a new first-period settlement and re-authorizes the server key, bounded only by the subscription expiry and the chain\u0027s own semantics for re-installing an existing key.\n\nThis issue affects mpp: from 0.14.0 before 0.16.2."
}
],
"impacts": [
{
"capecId": "CAPEC-60",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAn attacker who obtains a payer\u0027s subscription activation credential (from a non-TLS hop, a log, a compromised intermediary, or the client\u0027s own retry buffer) can present it under fresh challenges to settle repeated first-period charges against that payer\u0027s wallet and re-authorize the server\u0027s access key. The payer bears the on-chain cost, limited only by the per-period subscription limit and the subscription expiry.\u003c/p\u003e"
},
{
"base64": false,
"type": "text/markdown",
"value": "An attacker who obtains a payer\u0027s subscription activation credential (from a non-TLS hop, a log, a compromised intermediary, or the client\u0027s own retry buffer) can present it under fresh challenges to settle repeated first-period charges against that payer\u0027s wallet and re-authorize the server\u0027s access key. The payer bears the on-chain cost, limited only by the per-period subscription limit and the subscription expiry."
}
],
"value": "An attacker who obtains a payer\u0027s subscription activation credential (from a non-TLS hop, a log, a compromised intermediary, or the client\u0027s own retry buffer) can present it under fresh challenges to settle repeated first-period charges against that payer\u0027s wallet and re-authorize the server\u0027s access key. The payer bears the on-chain cost, limited only by the per-period subscription limit and the subscription expiry."
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-294",
"description": "CWE-294 Authentication Bypass by Capture-replay",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T11:16:56.232Z",
"orgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"shortName": "EEF"
},
"references": [
{
"name": "GitHub Advisory",
"tags": [
"related",
"vendor-advisory"
],
"url": "https://github.com/ZenHive/mpp/security/advisories/GHSA-p9fv-9w58-95x2"
},
{
"name": "EEF CNA record for CVE-2026-87119",
"tags": [
"related"
],
"url": "https://cna.erlef.org/cves/CVE-2026-87119.html"
},
{
"name": "OSV record EEF-CVE-2026-87119",
"tags": [
"related"
],
"url": "https://osv.dev/vulnerability/EEF-CVE-2026-87119"
},
{
"name": "Introducing commit db464df in ZenHive/mpp",
"tags": [
"related"
],
"url": "https://github.com/ZenHive/mpp/commit/db464dfa9a86ccda58f0827101f6da6bd8aafa78"
},
{
"name": "Fix commit 4b6eaec in ZenHive/mpp",
"tags": [
"patch"
],
"url": "https://github.com/ZenHive/mpp/commit/4b6eaec02af0e8485cfb4ff68f467d075ed5dd6f"
}
],
"source": {
"discovery": "INTERNAL"
},
"title": "mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed"
}
},
"cveMetadata": {
"assignerOrgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"assignerShortName": "EEF",
"cveId": "CVE-2026-87119",
"datePublished": "2026-09-22T11:16:56.232Z",
"dateReserved": "2026-09-11T18:00:02.032Z",
"dateUpdated": "2026-09-22T12:02:31.484Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-86219 (GCVE-0-2026-86219)
Vulnerability from cvelistv5 – Published: 2026-09-06 17:46 – Updated: 2026-09-08 18:54- CWE-294 - Authentication Bypass by Capture-replay
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2026-86219",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-08T18:54:38.530817Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T18:54:55.841Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://cpan.org/modules",
"defaultStatus": "unaffected",
"modules": [
"Authen::SASL::Perl::DIGEST_MD5"
],
"packageName": "Authen-SASL",
"packageURL": "pkg:cpan/Authen-SASL",
"programFiles": [
"lib/Authen/SASL/Perl/DIGEST_MD5.pm"
],
"programRoutines": [
{
"name": "Authen::SASL::Perl::DIGEST_MD5::server_step"
},
{
"name": "Authen::SASL::Perl::DIGEST_MD5::server_start"
}
],
"repo": "https://github.com/perl-authen-sasl/perl-authen-sasl",
"versions": [
{
"lessThan": "2.2100",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step.\n\nserver_start generates a fresh nonce and sends it in the challenge, and nothing later compares that value against the nonce the client returns. server_step derives the expected digest from the client\u0027s own parameters, so a response verifies whenever its digest matches the nonce it carries. The count table it also checks is keyed on the client-supplied nonce and starts empty in each new server object, so a captured first response, carrying `nc=00000001`, passes that too. RFC 2831 defines the nonce in the response as the value the server sent in the preceding challenge.\n\nAn attacker who observes one successful `qop=auth` exchange can replay the captured response against a later session for the same service, host, realm and user, and authenticate as that user without knowing the password."
}
],
"impacts": [
{
"capecId": "CAPEC-115",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-115 Authentication Bypass"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-294",
"description": "CWE-294 Authentication Bypass by Capture-replay",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-06T17:46:30.340Z",
"orgId": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"shortName": "CPANSec"
},
"references": [
{
"url": "https://metacpan.org/release/EHUELS/Authen-SASL-2.2000/source/lib/Authen/SASL/Perl/DIGEST_MD5.pm#L203-222"
},
{
"url": "https://metacpan.org/release/EHUELS/Authen-SASL-2.2000/source/lib/Authen/SASL/Perl/DIGEST_MD5.pm#L410-414"
},
{
"url": "https://datatracker.ietf.org/doc/html/rfc2831#section-2.1.2"
},
{
"tags": [
"patch"
],
"url": "https://github.com/perl-authen-sasl/perl-authen-sasl/commit/94337367030612842924f697cead29964a96448d.patch"
},
{
"tags": [
"release-notes"
],
"url": "https://metacpan.org/release/EHUELS/Authen-SASL-2.2100/changes"
},
{
"tags": [
"related"
],
"url": "https://www.cve.org/CVERecord?id=CVE-2025-40918"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to Authen-SASL 2.2100 or later."
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step",
"x_generator": {
"engine": "cpansec-cna-tool 0.1"
}
}
},
"cveMetadata": {
"assignerOrgId": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"assignerShortName": "CPANSec",
"cveId": "CVE-2026-86219",
"datePublished": "2026-09-06T17:46:30.340Z",
"dateReserved": "2026-09-06T00:13:35.358Z",
"dateUpdated": "2026-09-08T18:54:55.841Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-84306 (GCVE-0-2026-84306)
Vulnerability from cvelistv5 – Published: 2026-09-01 19:10 – Updated: 2026-09-04 02:06- CWE-294 - Authentication Bypass by Capture-replay
| URL | Tags |
|---|---|
| https://github.com/filamentphp/filament/security/… | x_refsource_CONFIRM |
| https://github.com/filamentphp/filament/pull/20335 | x_refsource_MISC |
| https://github.com/filamentphp/filament/commit/b6… | x_refsource_MISC |
| https://github.com/filamentphp/filament/releases/… | x_refsource_MISC |
| https://github.com/filamentphp/filament/releases/… | x_refsource_MISC |
| Vendor | Product | Version | |
|---|---|---|---|
| filamentphp | filament |
Affected:
>= 4.0.0, < 4.12.6
Affected: >= 5.0.0, < 5.7.6 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-84306",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T02:06:10.316293Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T02:06:19.110Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "filament",
"vendor": "filamentphp",
"versions": [
{
"status": "affected",
"version": "\u003e= 4.0.0, \u003c 4.12.6"
},
{
"status": "affected",
"version": "\u003e= 5.0.0, \u003c 5.7.6"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.6 and 5.7.6, packages/panels/src/Auth/MultiFactor/App/AppAuthentication.php uses AppAuthentication::verifyCode() with a used-code cache key derived from both the app authentication secret and the submitted TOTP code. This isolates the newest accepted timestep by code instead of by secret, allowing a previously issued app-based MFA code to be accepted after a newer code has already been used. Reuse of the exact same code was already prevented, but another code inside the accepted time window remained usable. An attacker who obtains the target account\u0027s password and one app-based MFA code can use that code for the remainder of the configured window, which is approximately four minutes with the default settings, even after the legitimate account holder logs in with a newer code. Email-based MFA is not affected. This issue is fixed in versions 4.12.6 and 5.7.6."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-294",
"description": "CWE-294: Authentication Bypass by Capture-replay",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-01T19:10:47.969Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/filamentphp/filament/security/advisories/GHSA-r3j6-gpjw-qfjr",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/filamentphp/filament/security/advisories/GHSA-r3j6-gpjw-qfjr"
},
{
"name": "https://github.com/filamentphp/filament/pull/20335",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/filamentphp/filament/pull/20335"
},
{
"name": "https://github.com/filamentphp/filament/commit/b6bde8572bcac75d4f5b4ec892ba7b9e91e0ab4d",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/filamentphp/filament/commit/b6bde8572bcac75d4f5b4ec892ba7b9e91e0ab4d"
},
{
"name": "https://github.com/filamentphp/filament/releases/tag/v4.12.6",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/filamentphp/filament/releases/tag/v4.12.6"
},
{
"name": "https://github.com/filamentphp/filament/releases/tag/v5.7.6",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/filamentphp/filament/releases/tag/v5.7.6"
}
],
"source": {
"advisory": "GHSA-r3j6-gpjw-qfjr",
"discovery": "UNKNOWN"
},
"title": "Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-84306",
"datePublished": "2026-09-01T19:10:47.969Z",
"dateReserved": "2026-09-01T16:17:43.078Z",
"dateUpdated": "2026-09-04T02:06:19.110Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-84003 (GCVE-0-2026-84003)
Vulnerability from cvelistv5 – Published: 2026-09-08 17:19 – Updated: 2026-10-01 23:01- CWE-294 - Authentication Bypass by Capture-replay
| URL | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerabi… | vendor-advisorypatch |
| Vendor | Product | Version | |
|---|---|---|---|
| Microsoft | Microsoft Authentication Library |
Affected:
1.0.0 , < 5.6.0
(custom)
cpe:2.3:a:microsoft:microsoft_authentication_library_for_node.js:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-84003",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-11T20:49:07.570578Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-11T20:49:18.803Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "Microsoft Authentication Library",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "5.6.0",
"status": "affected",
"version": "1.0.0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:microsoft_authentication_library_for_node.js:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.6.0",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"datePublic": "2026-09-08T14:00:00.000Z",
"descriptions": [
{
"lang": "en-US",
"value": "Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-294",
"description": "CWE-294: Authentication Bypass by Capture-replay",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T23:01:14.881Z",
"orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"shortName": "microsoft"
},
"references": [
{
"name": "Microsoft Authentication Library (MSAL) for Node.js Spoofing Vulnerability",
"tags": [
"vendor-advisory",
"patch"
],
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-84003"
}
],
"title": "Microsoft Authentication Library (MSAL) for Node.js Spoofing Vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"assignerShortName": "microsoft",
"cveId": "CVE-2026-84003",
"datePublished": "2026-09-08T17:19:32.079Z",
"dateReserved": "2026-09-01T01:16:35.985Z",
"dateUpdated": "2026-10-01T23:01:14.881Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-82470 (GCVE-0-2026-82470)
Vulnerability from cvelistv5 – Published: 2026-08-29 16:35 – Updated: 2026-08-31 18:16- CWE-294 - Authentication Bypass by Capture-replay
| URL | Tags |
|---|---|
| https://github.com/jeremyevans/rodauth/commit/3bf… | patch |
| https://github.com/jeremyevans/rodauth/security/a… | vendor-advisory |
| https://github.com/jeremyevans/rodauth | product |
| https://www.vulncheck.com/advisories/rodauth-befo… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| jeremyevans | rodauth |
Affected:
0 , < 2.47.0
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-82470",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-31T18:13:50.960880Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-31T18:16:06.572Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "rodauth",
"vendor": "jeremyevans",
"versions": [
{
"lessThan": "2.47.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Joshua Rogers (AISLE Research)"
}
],
"datePublic": "2026-08-23T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted code timestamp. Attackers who observe a valid TOTP code can replay it during the drift window to bypass the second authentication factor."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "HIGH",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-294",
"description": "Authentication Bypass by Capture-replay",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-29T16:35:31.777Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/jeremyevans/rodauth/commit/3bfd0a11bae70935b1944e71dbe787dd0c3a62ad"
},
{
"name": "GitHub Security Advisory (GHSA-hhvg-6qmv-58vc)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/jeremyevans/rodauth/security/advisories/GHSA-hhvg-6qmv-58vc"
},
{
"tags": [
"product"
],
"url": "https://github.com/jeremyevans/rodauth"
},
{
"name": "VulnCheck Advisory: Rodauth before 2.47.0 TOTP Code Reuse via Drift Window",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/rodauth-before-2.47.0-totp-code-reuse-via-drift-window"
}
],
"title": "Rodauth before 2.47.0 TOTP Code Reuse via Drift Window",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-82470",
"datePublished": "2026-08-29T16:35:31.777Z",
"dateReserved": "2026-08-29T14:11:08.152Z",
"dateUpdated": "2026-08-31T18:16:06.572Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Mitigation
Utilize some sequence or time stamping functionality along with a checksum which takes this into account in order to ensure that messages can be parsed only once.
Mitigation
Since any attacker who can listen to traffic can see sequence numbers, it is necessary to sign messages with some kind of cryptography to ensure that sequence numbers are not simply doctored along with content.
CAPEC-102: Session Sidejacking
Session sidejacking takes advantage of an unencrypted communication channel between a victim and target system. The attacker sniffs traffic on a network looking for session tokens in unencrypted traffic. Once a session token is captured, the attacker performs malicious actions by using the stolen token with the targeted application to impersonate the victim. This attack is a specific method of session hijacking, which is exploiting a valid session token to gain unauthorized access to a target system or information. Other methods to perform a session hijacking are session fixation, cross-site scripting, or compromising a user or server machine and stealing the session token.
CAPEC-509: Kerberoasting
Through the exploitation of how service accounts leverage Kerberos authentication with Service Principal Names (SPNs), the adversary obtains and subsequently cracks the hashed credentials of a service account target to exploit its privileges. The Kerberos authentication protocol centers around a ticketing system which is used to request/grant access to services and to then access the requested services. As an authenticated user, the adversary may request Active Directory and obtain a service ticket with portions encrypted via RC4 with the private key of the authenticated account. By extracting the local ticket and saving it disk, the adversary can brute force the hashed value to reveal the target account credentials.
CAPEC-555: Remote Services with Stolen Credentials
This pattern of attack involves an adversary that uses stolen credentials to leverage remote services such as RDP, telnet, SSH, and VNC to log into a system. Once access is gained, any number of malicious activities could be performed.
CAPEC-561: Windows Admin Shares with Stolen Credentials
An adversary guesses or obtains (i.e. steals or purchases) legitimate Windows administrator credentials (e.g. userID/password) to access Windows Admin Shares on a local machine or within a Windows domain.
CAPEC-60: Reusing Session IDs (aka Session Replay)
This attack targets the reuse of valid session ID to spoof the target system in order to gain privileges. The attacker tries to reuse a stolen session ID used previously during a transaction to perform spoofing and session hijacking. Another name for this type of attack is Session Replay.
CAPEC-644: Use of Captured Hashes (Pass The Hash)
An adversary obtains (i.e. steals or purchases) legitimate Windows domain credential hash values to access systems within the domain that leverage the Lan Man (LM) and/or NT Lan Man (NTLM) authentication protocols.
CAPEC-645: Use of Captured Tickets (Pass The Ticket)
An adversary uses stolen Kerberos tickets to access systems/resources that leverage the Kerberos authentication protocol. The Kerberos authentication protocol centers around a ticketing system which is used to request/grant access to services and to then access the requested services. An adversary can obtain any one of these tickets (e.g. Service Ticket, Ticket Granting Ticket, Silver Ticket, or Golden Ticket) to authenticate to a system/resource without needing the account's credentials. Depending on the ticket obtained, the adversary may be able to access a particular resource or generate TGTs for any account within an Active Directory Domain.
CAPEC-652: Use of Known Kerberos Credentials
An adversary obtains (i.e. steals or purchases) legitimate Kerberos credentials (e.g. Kerberos service account userID/password or Kerberos Tickets) with the goal of achieving authenticated access to additional systems, applications, or services within the domain.
CAPEC-701: Browser in the Middle (BiTM)
An adversary exploits the inherent functionalities of a web browser, in order to establish an unnoticed remote desktop connection in the victim's browser to the adversary's system. The adversary must deploy a web client with a remote desktop session that the victim can access.
CAPEC-94: Adversary in the Middle (AiTM)
An adversary targets the communication between two components (typically client and server), in order to alter or obtain data from transactions. A general approach entails the adversary placing themself within the communication channel between the two components.