{"id":"CVE-2026-105835","summary":"PLANKA 2.2.0 through 2.2.1 TOTP Brute Force via verify-totp Endpoint","details":"PLANKA 2.2.0 through 2.2.1 fails to limit incorrect TOTP codes submitted to POST /api/access-tokens/verify-totp, allowing attackers to brute force two-factor authentication codes. Attackers who know a user's password can reuse the ten-minute pending token to guess six-digit codes until one succeeds, obtaining a full access token.","modified":"2026-10-08T02:51:17.536896939Z","published":"2026-10-06T12:57:55.187Z","database_specific":{"cwe_ids":["CWE-307"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105835.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105835.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105835"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/planka-2.2.0-through-2.2.1-totp-brute-force-via-verify-totp-endpoint"},{"type":"FIX","url":"https://github.com/plankanban/planka/commit/de4d7688317829e2a0b665fe9dbf39eaf127b6f9"},{"type":"PACKAGE","url":"https://github.com/plankanban/planka"},{"type":"ARTICLE","url":"https://github.com/plankanban/planka/blob/v2.2.1/server/api/controllers/access-tokens/verify-totp.js"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/plankanban/planka","events":[{"introduced":"2684198bf88d92baf0cd599407231b36d6686fd0"},{"fixed":"266246e242430d921c32badecdd447514107c568"},{"fixed":"de4d7688317829e2a0b665fe9dbf39eaf127b6f9"}],"database_specific":{"source":["DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"2.2.0"},{"fixed":"2.2.1"}]}}],"versions":["v2.2.0","planka-2.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105835.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}