Integer Coercion Vulnerability in Punk::Plugin::TOTP for Perl
CVE-2026-78619
Currently unrated
What is CVE-2026-78619?
The Punk::Plugin::TOTP for Perl contains a vulnerability that allows a malicious user to bypass two-factor authentication. This occurs when the recovery code submission process improperly evaluates user identifiers due to integer coercion, allowing an attacker to authenticate as a different user if they know the victim's password and possess a valid recovery code. The flaw lies in the numeric comparison mechanism, which can lead to incorrect ownership verification of recovery codes across user accounts.
