CVE-2026-94112: mayswind ezBookkeeping before 2.0.0 TOTP Replay Attack

Published Sep 20, 2026
·
Updated

mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window. Attackers with stolen credentials can authenticate and reuse a captured passcode against multiple authorization attempts for approximately 90 seconds without detection.

Affected Software

1 affected component
MaysWind ezBookkeeping<2.0.0

Event History

Sep 20, 2026
CVE Published
via MITRE·11:56 AM
Data Sourced
via MITRE·11:56 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Deployments of MaysWind ezBookkeeping earlier than 2.0.0 are affected where TOTP authentication is used. An attacker also needs stolen credentials and a captured valid TOTP passcode.

2

What can an attacker do with a captured passcode?

The same captured TOTP passcode can be replayed for multiple authorization attempts during its acceptance window, approximately 90 seconds. Successful replay allows authentication when used with stolen credentials.

3

Are repeated uses of a captured TOTP code detected?

No. The issue description states that passcodes can be reused against multiple authorization attempts without detection during the acceptance window.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203