CVE-2026-105835
Received Received - Intake

TOTP Brute Force in Planka Application

Vulnerability report for CVE-2026-105835, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: VulnCheck

Description

PLANKA 2.2.0 through 2.2.1 fails to limit incorrect TOTP codes submitted to POST /api/access-tokens/verify-totp, allowing attackers to brute force two-factor authentication codes. Attackers who know a user's password can reuse the ten-minute pending token to guess six-digit codes until one succeeds, obtaining a full access token.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
planka planka 2.2.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-307 The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

PLANKA versions 2.2.0 to 2.2.1 do not properly restrict repeated attempts to submit incorrect TOTP codes via the POST /api/access-tokens/verify-totp endpoint. This allows attackers to brute force six-digit two-factor authentication codes within a ten-minute window if they already know the user's password. Successful guesses grant access to the user's full account.

Detection Guidance

Monitor POST requests to /api/access-tokens/verify-totp for repeated failed TOTP attempts within a short timeframe. Check server logs for multiple six-digit code submissions from the same IP or user account.

Impact Analysis

If you use PLANKA 2.2.0 or 2.2.1 and your password is compromised, attackers can bypass two-factor authentication by repeatedly guessing the TOTP code. This could lead to unauthorized access to your account, data theft, or further exploitation of the system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements. Organizations may face compliance breaches, legal penalties, and reputational damage if user data is exposed due to insufficient authentication controls.

Mitigation Strategies

Upgrade PLANKA to a version beyond 2.2.1 that fixes the TOTP verification flaw. Implement rate limiting on the /api/access-tokens/verify-totp endpoint to prevent brute force attempts. Consider disabling pending tokens after a single failed attempt.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105835. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart