{"id":"CVE-2026-94112","summary":"mayswind ezBookkeeping before 2.0.0 TOTP Replay Attack","details":"mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window. Attackers with stolen credentials can authenticate and reuse a captured passcode against multiple authorization attempts for approximately 90 seconds without detection.","aliases":["GHSA-p6qr-48g6-97q3"],"modified":"2026-09-23T03:30:33.001122889Z","published":"2026-09-20T11:56:07.691Z","database_specific":{"cwe_ids":["CWE-294"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94112.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94112.json"},{"type":"ADVISORY","url":"https://github.com/mayswind/ezbookkeeping/releases/tag/v2.0.0"},{"type":"ADVISORY","url":"https://github.com/mayswind/ezbookkeeping/security/advisories/GHSA-p6qr-48g6-97q3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94112"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/mayswind-ezbookkeeping-before-2.0.0-totp-replay-attack"},{"type":"FIX","url":"https://github.com/mayswind/ezbookkeeping/commit/3dd6286d7a3ab0f980a6d36339b9c9c4df9467e4"},{"type":"PACKAGE","url":"https://github.com/mayswind/ezbookkeeping"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mayswind/ezbookkeeping","events":[{"introduced":"0"},{"fixed":"b2a3f4ede42c8a7aa3bab1e6dbbc7b8e6196ef35"},{"fixed":"3dd6286d7a3ab0f980a6d36339b9c9c4df9467e4"}],"database_specific":{"source":["DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"2.0.0"}]}}],"versions":["v1.6.0","v1.5.1","v1.5.0","v1.4.0","v1.3.2","v1.3.1","v1.3.0","v1.2.0","v1.1.0","v1.0.0","v0.10.0","v0.9.0","v0.8.0","v0.7.0","v0.6.0","v0.5.0","v0.4.0","v0.3.0","v0.2.0","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94112.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}