Junglewise Threat Intelligence

CVE-2026-78655: Punk::Plugin::TOTP session cookie replay bypass of second-factor attempt limit

CVE-2026-78655 · Severity: critical · CVSS 9.1 · Published 2026-08-25

Executive brief

Punk::Plugin::TOTP is a second-factor authentication module for Perl web applications that uses time-based one-time passwords (TOTP). A flaw in cookie-based session handling allows an attacker to replay a saved session cookie to reset the failed authentication attempt counter, effectively bypassing the rate limit on second-factor guessing and enabling brute-force attacks on TOTP codes.

Technical details

The vulnerability is a session replay issue in the TOTP challenge handler. The plugin stores the failed-attempt counter (tries) in a pending_totp record within a signed session cookie. When the default cookie-based session store is used (no server-side store declared), an attacker who saves the cookie before exhausting the attempt limit (default: 5) can replay it to reset the counter, bypassing the per-code attempt protection. The attack is time-bounded only by the pending_ttl window (default 300 seconds from challenge initiation). While a per-IP rate limit (30 requests/60 sec) exists, it does not prevent systematic guessing of the 6-digit TOTP code within this window. Applications using a server-side session store are not affected.

Affected products

  • LNATION Punk::Plugin::TOTP before 0.05

Timeline

  • 2026-08-25: disclosed

References

Related threats