TOTP Replay Vulnerability in mayswind ezBookkeeping Software
CVE-2026-94112

7.6HIGH

Key Information:

Vendor

Mayswind

Vendor
CVE Published:
20 September 2026

What is CVE-2026-94112?

The mayswind ezBookkeeping application, prior to version 2.0.0, contains a vulnerability wherein Time-based One-Time Password (TOTP) passcodes are not invalidated after their initial use. This oversight enables attackers to replay intercepted codes within a 90-second window, facilitating unauthorized access. An attacker equipped with stolen credentials can authenticate multiple authorization attempts using a captured passcode without detection, posing significant security risks to user accounts.

Affected Version(s)

ezBookkeeping 0 < 2.0.0

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Waleed Hassan (GhostOverflow)
.