CVE-2026-94112

Source
https://cve.org/CVERecord?id=CVE-2026-94112
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94112.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-94112
Aliases
  • GHSA-p6qr-48g6-97q3
Published
2026-09-20T11:56:07Z
Modified
2026-09-23T03:30:33Z
Severity
  • 7.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
mayswind ezBookkeeping before 2.0.0 TOTP Replay Attack
Details

mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window. Attackers with stolen credentials can authenticate and reuse a captured passcode against multiple authorization attempts for approximately 90 seconds without detection.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-294"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94112.json"
}
References

Affected packages

Git / github.com/mayswind/ezbookkeeping

Affected ranges

Type
GIT
Repo
https://github.com/mayswind/ezbookkeeping
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "2.0.0"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.1.0
v0.10.0
v0.2.0
v0.3.0
v0.4.0
v0.5.0
v0.6.0
v0.7.0
v0.8.0
v0.9.0
v1.*
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.3.2
v1.4.0
v1.5.0
v1.5.1
v1.6.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94112.json"