CVE-2026-32729: Runtipi has a TOTP two-factor authentication bypass via unrestricted brute-force on `/api/auth/verify-totp`

Published Mar 13, 2026
·
Updated

Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enforce any rate limiting, attempt counting, or account lockout mechanism. An attacker who has obtained a user's valid credentials (via phishing, credential stuffing, or data breach) can brute-force the 6-digit TOTP code to completely bypass two-factor authentication. The TOTP verification session persists for 24 hours (default cache TTL), providing an excessive window during which the full 1,000,000-code keyspace (000000–999999) can be exhausted. At practical request rates (~500 req/s), the attack completes in approximately 33 minutes in the worst case. This vulnerability is fixed in 4.8.1.

Affected Software

2 affected components
Runtipi Runtipi<4.8.1
Runtipi Runtipi<4.8.1

Event History

Mar 13, 2026
CVE Published
via MITRE·09:41 PM
Data Sourced
via MITRE·09:41 PM
DescriptionSeverityWeakness
Mar 16, 2026
Data Sourced
via NVD·02:19 PM
DescriptionSeverityWeaknessAffected Software
Jul 22, 58183
Event
via FIRST·04:12 AM

Frequently Asked Questions

1

What is the severity of CVE-2026-32729?

CVE-2026-32729 is considered a high severity vulnerability due to its potential for unauthorized access.

2

How do I fix CVE-2026-32729?

To fix CVE-2026-32729, update Runtipi to version 4.8.1 or later, which implements proper rate limiting.

3

What kind of attack does CVE-2026-32729 allow?

CVE-2026-32729 allows attackers to brute-force the TOTP verification process due to lack of rate limiting and account lockout.

4

Which versions of Runtipi are affected by CVE-2026-32729?

All versions of Runtipi prior to 4.8.1 are affected by CVE-2026-32729.

5

Is there a workaround for CVE-2026-32729 if I cannot update immediately?

There is no official workaround for CVE-2026-32729; upgrading to a secure version is the recommended approach.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203