high · CVSS v3 6.8 · CVSS v4 7.6
CVE-2026-94112
mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured …
Description
mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window. Attackers with stolen credentials can authenticate and reuse a captured passcode against multiple authorization attempts for approximately 90 seconds without detection.
Scores
- Severity
- high
- CVSS v2
- 7.1
- CVSS v3
- 6.8
- CVSS v4
- 7.6
- EPSS
- —