CVE-2026-94112: mayswind ezBookkeeping before 2.0.0 TOTP Replay Attack
mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window. Attackers with stolen credentials can authenticate and reuse a captured passcode against multiple authorization attempts for approximately 90 seconds without detection.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments of MaysWind ezBookkeeping earlier than 2.0.0 are affected where TOTP authentication is used. An attacker also needs stolen credentials and a captured valid TOTP passcode.
What can an attacker do with a captured passcode?
The same captured TOTP passcode can be replayed for multiple authorization attempts during its acceptance window, approximately 90 seconds. Successful replay allows authentication when used with stolen credentials.
Are repeated uses of a captured TOTP code detected?
No. The issue description states that passcodes can be reused against multiple authorization attempts without detection during the acceptance window.