Integer Coercion Vulnerability in Punk::Plugin::TOTP for Perl
CVE-2026-78619

Currently unrated

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-78619?

The Punk::Plugin::TOTP for Perl contains a vulnerability that allows a malicious user to bypass two-factor authentication. This occurs when the recovery code submission process improperly evaluates user identifiers due to integer coercion, allowing an attacker to authenticate as a different user if they know the victim's password and possess a valid recovery code. The flaw lies in the numeric comparison mechanism, which can lead to incorrect ownership verification of recovery codes across user accounts.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.