CVE-2026-94206
Received Received - Intake

Password Hash With Insufficient Computational Effort in Cloak Ecto

Vulnerability report for CVE-2026-94206, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: EEF

Description

Use of Password Hash With Insufficient Computational Effort vulnerability in danielberkompas cloak_ecto and danielberkompas cloak allows an attacker who holds the hashed values and the configured secret to brute-force low-entropy plaintexts much faster than configured. The dump/1 callback that Cloak.Ecto.PBKDF2 (Cloak.Fields.PBKDF2 in cloak before the Ecto code moved to cloak_ecto) injects into a field module calls :pbkdf2.pbkdf2/4 with config[:size] in the iteration-count position. The :iterations setting is validated but never used. With the cloak_ecto defaults (iterations: 600_000, size: 32) each hash runs 32 PBKDF2 rounds instead of 600,000, so offline guessing of values such as email addresses costs about 18,750 times less than configured. This issue affects cloak_ecto: from 1.0.0-alpha.0 onward; cloak: from 0.7.0 before 1.0.0-alpha.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
danielberkompas cloak_ecto 1.0.0-alpha.0
danielberkompas cloak_ecto a8fa1642b02f1c445a1ee8794c9095eb0921f8f3
danielberkompas cloak 0.7.0
danielberkompas cloak 8699e6417a162c39d9f0ef63511bd23d3f38d1d2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-916 The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the use of password hashing with insufficient computational effort. The Cloak.Ecto.PBKDF2 function incorrectly uses the size parameter as the iteration count in the PBKDF2 algorithm, reducing security. Instead of using the configured 600,000 iterations, it only performs 32 rounds, making brute-force attacks 18,750 times faster.

Detection Guidance

This vulnerability is specific to the Cloak library's PBKDF2 implementation. Detection requires checking if the affected versions of cloak or cloak_ecto are in use and verifying if the :iterations setting is not being applied correctly in the PBKDF2 hash generation.

Impact Analysis

If you use affected versions of cloak_ecto or cloak, attackers with access to hashed values and the secret key could crack low-entropy plaintexts like email addresses much faster. This weakens security for stored credentials and sensitive data.

Mitigation Strategies

Upgrade to the latest patched versions of cloak and cloak_ecto where the issue has been resolved. Ensure the :iterations parameter is correctly applied in the PBKDF2 configuration to restore the intended computational effort for password hashing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94206. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart