Time-Based OTP Reuse Vulnerability in Rodauth by Jeremy Evans
CVE-2026-82470
5.1MEDIUM
What is CVE-2026-82470?
Rodauth versions prior to 2.47.0 exhibit a vulnerability within their OTP feature that inadequately tracks the timestamp of the last accepted code. This oversight allows attackers to exploit the time-based one-time password (TOTP) mechanism by replaying valid codes within a drift window, effectively bypassing the second layer of authentication and compromising user security. It's crucial for users to update to the latest version to mitigate this risk.
Affected Version(s)
rodauth 0 < 2.47.0
