Junglewise Threat Intelligence

CVE-2026-78619: Punk::Plugin::TOTP recovery code validation bypass

CVE-2026-78619 · Severity: critical · CVSS 9.8 · Published 2026-08-25

Executive brief

Punk::Plugin::TOTP is a two-factor authentication library for Perl applications. A flaw in how it validates recovery codes allows an attacker who knows a victim's password and possesses any valid recovery code to bypass two-factor authentication and gain unauthorized access to victim accounts. This effectively defeats the second factor protection for all affected users.

Technical details

Punk::Plugin::TOTP versions before 0.05 contain an authentication bypass in the totp_use_recovery helper function. The vulnerability stems from improper user identity validation when checking recovery code ownership: the function searches for a submitted recovery code digest across all users' rows without initially filtering by user, then relies on a secondary ownership test that compares user_id values using Perl's numeric coercion. User identifiers that contain no leading digits coerce to zero in Perl, causing any two non-numeric identifiers to incorrectly compare as equal. This affects systems using username, email address, or UUID as keys. An attacker with knowledge of a victim's password can submit their own recovery code, which passes the (broken) ownership check, and successfully authenticate as the victim after TOTP verification fails. The vulnerability requires knowledge of both the victim's password and possession of a valid recovery code from any account.

Affected products

  • LNATION Punk::Plugin::TOTP before 0.05

Timeline

  • 2026-08-25: disclosed
  • other: CVE-2026-78619 assigned

References

Related threats