Skip to main content
EPSS 0.5%top 59%

CVE-2026-78655: CWE-307 Improper Restriction of Excessive Authentication Attempts

0
Critical
Published: 08/25/2026 (08/25/2026, 21:23:48 UTC)
Source: CVE Database V5

Description

Punk::Plugin::TOTP versions before 0.05 for Perl have a vulnerability where the second-factor authentication attempt limit can be bypassed by replaying an earlier session cookie. This occurs because the failure count is stored in the session cookie rather than server-side, allowing an attacker to reset the failure count by reusing a previous cookie. Applications using server-side session stores are not affected. The vulnerability allows unlimited guessing of the second factor within the constraints of a separate per-address rate limit.

CVSS v3.1

Score 9.1critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/09/2026, 21:07:34 UTC

Technical Analysis

The vulnerability in Punk::Plugin::TOTP (prior to version 0.05) arises from improper restriction of excessive authentication attempts (CWE-307). The plugin tracks second-factor authentication failures in a session cookie (client-side) rather than server-side, enabling an attacker to replay an earlier session cookie to reset the failure count and bypass the attempt limit. The session cookie is signed but contains the failure count and pending record, which remain valid until expiry. Applications that configure a server-side session store are not vulnerable because the failure count is then maintained server-side. The plugin also enforces a per-address rate limit of 30 requests per 60 seconds, which is separate from the vulnerable attempt limit mechanism.

Potential Impact

An attacker can bypass the second-factor authentication attempt limit by replaying a previously saved session cookie, allowing unlimited attempts to guess the second-factor code within the cookie's expiry time. This can lead to compromise of accounts protected by the vulnerable plugin if the second-factor code is guessed or brute-forced. The vulnerability affects confidentiality and integrity but does not impact availability. Applications using server-side session stores are not affected.

Mitigation Recommendations

No official fix or patch is currently documented for this vulnerability. Users should configure Punk::Plugin::TOTP to use a server-side session store, which prevents the failure count from being stored client-side and mitigates the issue. Additionally, the plugin's per-address rate limiting remains effective and should be maintained. Monitor vendor advisories for updates or official patches addressing this issue.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
CPANSec
Date Reserved
2026-08-24T23:12:17.196Z
State
PUBLISHED

Threat ID: 6a8e0b22acd9273b49bc7090

Added to database: 08/25/2026, 21:37:38 UTC

Last enriched: 09/09/2026, 21:07:34 UTC

Last updated: 10/07/2026, 18:48:23 UTC

Views: 72

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses