Brute Force Vulnerability in PLANKA's Two-Factor Authentication Mechanism
CVE-2026-105835
9.1CRITICAL
What is CVE-2026-105835?
The PLANKA application, in versions 2.2.0 and 2.2.1, contains a vulnerability that fails to adequately limit the submission of incorrect Time-based One-Time Passwords (TOTP) via the verify-totp endpoint. This shortcoming allows malicious actors, who may already possess a user's password, to exploit two-factor authentication by repeatedly guessing six-digit codes. By attempting this brute-force attack using a reusable ten-minute pending token, attackers can eventually pinpoint the correct code and unlawfully obtain a full access token, compromising user accounts.
Affected Version(s)
planka 2.2.0 <= 2.2.1
