CVE-2026-105835: PLANKA 2.2.0 through 2.2.1 TOTP Brute Force via verify-totp Endpoint
Published Oct 6, 2026
·Updated
PLANKA 2.2.0 through 2.2.1 fails to limit incorrect TOTP codes submitted to POST /api/access-tokens/verify-totp, allowing attackers to brute force two-factor authentication codes. Attackers who know a user's password can reuse the ten-minute pending token to guess six-digit codes until one succeeds, obtaining a full access token.
Affected Software
1 affected component
planka planka>=2.2.0<=2.2.1
Event History
Oct 6, 2026
CVE Published
via MITRE·12:57 PM
Data Sourced
via MITRE·12:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need before they can brute-force the TOTP code?
The attacker must know the targeted user's password. They can then use the ten-minute pending token to submit guesses to the TOTP verification endpoint.
2
Which deployments are affected?
PLANKA versions 2.2.0 through 2.2.1 are affected. The issue is in POST /api/access-tokens/verify-totp, which does not limit incorrect TOTP submissions.
3
What access can an attacker obtain if a code guess succeeds?
A successful six-digit TOTP guess results in a full access token for the targeted account.