CVE-2026-94112
6.8 MEDIUMpublic exploit availablePublished 2026-09-20 · Updated 2026-09-21
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window. Attackers with stolen credentials can authenticate and reuse a captured passcode against multiple authorization attempts for approximately 90 seconds without detection.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Weaknesses
CWE-294
Public exploit & PoC references
All references
- https://github.com/mayswind/ezbookkeeping/commit/3dd6286d7a3ab0f980a6d36339b9c9c4df9467e4
- https://github.com/mayswind/ezbookkeeping/releases/tag/v2.0.0
- https://github.com/mayswind/ezbookkeeping/security/advisories/GHSA-p6qr-48g6-97q3
- https://www.vulncheck.com/advisories/mayswind-ezbookkeeping-before-2.0.0-totp-replay-attack
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.