CVE-2026-78655: CWE-307 Improper Restriction of Excessive Authentication Attempts
Description
Punk::Plugin::TOTP versions before 0.05 for Perl have a vulnerability where the second-factor authentication attempt limit can be bypassed by replaying an earlier session cookie. This occurs because the failure count is stored in the session cookie rather than server-side, allowing an attacker to reset the failure count by reusing a previous cookie. Applications using server-side session stores are not affected. The vulnerability allows unlimited guessing of the second factor within the constraints of a separate per-address rate limit.
CVSS v3.1
Score 9.1critical
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Punk::Plugin::TOTP (prior to version 0.05) arises from improper restriction of excessive authentication attempts (CWE-307). The plugin tracks second-factor authentication failures in a session cookie (client-side) rather than server-side, enabling an attacker to replay an earlier session cookie to reset the failure count and bypass the attempt limit. The session cookie is signed but contains the failure count and pending record, which remain valid until expiry. Applications that configure a server-side session store are not vulnerable because the failure count is then maintained server-side. The plugin also enforces a per-address rate limit of 30 requests per 60 seconds, which is separate from the vulnerable attempt limit mechanism.
Potential Impact
An attacker can bypass the second-factor authentication attempt limit by replaying a previously saved session cookie, allowing unlimited attempts to guess the second-factor code within the cookie's expiry time. This can lead to compromise of accounts protected by the vulnerable plugin if the second-factor code is guessed or brute-forced. The vulnerability affects confidentiality and integrity but does not impact availability. Applications using server-side session stores are not affected.
Mitigation Recommendations
No official fix or patch is currently documented for this vulnerability. Users should configure Punk::Plugin::TOTP to use a server-side session store, which prevents the failure count from being stored client-side and mitigates the issue. Additionally, the plugin's per-address rate limiting remains effective and should be maintained. Monitor vendor advisories for updates or official patches addressing this issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CPANSec
- Date Reserved
- 2026-08-24T23:12:17.196Z
- State
- PUBLISHED
Threat ID: 6a8e0b22acd9273b49bc7090
Added to database: 08/25/2026, 21:37:38 UTC
Last enriched: 09/09/2026, 21:07:34 UTC
Last updated: 10/07/2026, 18:48:23 UTC
Views: 72
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.