TOTP Replay in mayswind ezBookkeeping <2.0.0
CVE-2026-94112 Published on September 20, 2026
mayswind ezBookkeeping before 2.0.0 TOTP Replay Attack
mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window. Attackers with stolen credentials can authenticate and reuse a captured passcode against multiple authorization attempts for approximately 90 seconds without detection.
Vulnerability Analysis
CVE-2026-94112 is exploitable with network access. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Authentication Bypass by Capture-replay
A capture-replay flaw exists when the design of the software makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes). Capture-replay attacks are common and can be difficult to defeat without cryptography. They are a subset of network injection attacks that rely on observing previously-sent valid commands, then changing them slightly if necessary and resending the same commands to the server.
Products Associated with CVE-2026-94112
Want to know whenever a new CVE is published for Mayswind Ezbookkeeping? stack.watch will email you.
Affected Versions
mayswind ezBookkeeping:- Before 2.0.0 is affected.