Rodauth 2.47.0 之前的版本中存在一个基于时间的一次性密码(TOTP)重用漏洞,位于 OTP 功能中。由于该功能未能跟踪最后一次被接受验证码的时间戳,攻击者在观察到有效的 TOTP 代码后,可以在时间漂移窗口内重放该代码,从而绕过第二认证因子(2FA)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jeremyevans | rodauth | 0 ~ 2.47.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82466 | 8.7 HIGH | Rodauth before 2.46.0 Authentication Bypass via webauthn_login |
| CVE-2026-82469 | 5.4 MEDIUM | Rodauth before 2.47.0 Authentication Bypass via jwt_refresh |
| CVE-2026-82467 | 4.7 MEDIUM | Rodauth before 2.47.0 Open Redirect via Return-to Path |
| CVE-2026-82468 | 4.7 MEDIUM | Rodauth before 2.47.0 CSRF Protection Bypass via Content-Type |
No comments yet