{"id":"CVE-2026-105835","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-105835","summary":"PLANKA 2.2.0 through 2.2.1 fails to limit incorrect TOTP codes submitted to POST /api/access-tokens/verify-totp, allowing attackers to brute force two-factor authentication codes. Attackers…","details":"PLANKA 2.2.0 through 2.2.1 fails to limit incorrect TOTP codes submitted to POST /api/access-tokens/verify-totp, allowing attackers to brute force two-factor authentication codes. Attackers who know a user's password can reuse the ten-minute pending token to guess six-digit codes until one succeeds, obtaining a full access token.","published":"2026-10-06T13:16:46.760","modified":"2026-10-06T13:16:46.760","cvss":{"score":7.4,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/plankanban/planka/commit/de4d7688317829e2a0b665fe9dbf39eaf127b6f9","label":"plankanban/planka@de4d768"},"references":[{"type":"WEB","url":"https://github.com/plankanban/planka"},{"type":"WEB","url":"https://github.com/plankanban/planka/blob/v2.2.1/server/api/controllers/access-tokens/verify-totp.js"},{"type":"WEB","url":"https://github.com/plankanban/planka/commit/de4d7688317829e2a0b665fe9dbf39eaf127b6f9"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/planka-2.2.0-through-2.2.1-totp-brute-force-via-verify-totp-endpoint"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-10-06T13:16:46.760"}}