Brute Force Vulnerability in PLANKA's Two-Factor Authentication Mechanism
CVE-2026-105835

9.1CRITICAL

Key Information:

Vendor

Planka

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105835?

The PLANKA application, in versions 2.2.0 and 2.2.1, contains a vulnerability that fails to adequately limit the submission of incorrect Time-based One-Time Passwords (TOTP) via the verify-totp endpoint. This shortcoming allows malicious actors, who may already possess a user's password, to exploit two-factor authentication by repeatedly guessing six-digit codes. By attempting this brute-force attack using a reusable ten-minute pending token, attackers can eventually pinpoint the correct code and unlawfully obtain a full access token, compromising user accounts.

Affected Version(s)

planka 2.2.0 <= 2.2.1

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eldor Nabijonov
.