Brute-Force Vulnerability in Planka TOTP Authentication
Planka versions 2.2.0 through 2.2.1 contain a vulnerability in the TOTP verification endpoint that lacks rate-limiting, allowing attackers with known user passwords to brute-force two-factor authentication tokens.
CVE search metadata
CVE search record: CVE-2026-105835. Severity: high. CVSS: 7.4. KEV: no. Product: Planka (2.2.0-2.2.1). Brief: Brute-Force Vulnerability in Planka TOTP Authentication. Brief link: https://feed.craftedsignal.io/briefs/2026-10-planka-totp-brute-force/
Planka versions 2.2.0 through 2.2.1 are vulnerable to a brute-force attack targeting the two-factor authentication (2FA) mechanism. The vulnerability exists within the /api/access-tokens/verify-totp endpoint, which fails to implement rate-limiting or account lockout mechanisms for failed TOTP code submissions. If an attacker has obtained a user's password, they can leverage the ten-minute pending token issued by the application to systematically guess six-digit TOTP codes. Given the lack of throttling, an attacker can exhaustively attempt combinations until the correct token is identified, ultimately resulting in unauthorized access to the victim's account. This flaw represents a significant risk for organizations relying on the native 2FA implementation in Planka, as it effectively bypasses the second layer of security.
Attack Chain
- Attacker obtains a valid username and password through credential harvesting or other initial access methods.
- Attacker initiates the authentication process against the Planka instance using the compromised credentials.
- The server validates the password and returns a ten-minute valid pending token, prompting for the second-factor code.
- Attacker targets the /api/access-tokens/verify-totp endpoint with high-frequency HTTP POST requests.
- Attacker iterates through six-digit TOTP code combinations within the ten-minute window allowed by the pending token.
- The server fails to enforce rate limits or block the source IP after repeated failed attempts.
- Upon successfully guessing the correct code, the server returns a full session access token.
- Attacker uses the acquired access token to gain unauthorized entry to the application.
Impact
Successful exploitation of this vulnerability allows unauthorized actors to bypass 2FA, leading to full account takeover. The impact includes the potential for unauthorized access to project management data, sensitive information exposure, and further lateral movement within the compromised environment. This vulnerability affects all deployments of Planka versions 2.2.0 and 2.2.1.
Recommendation
Detection engineering teams should monitor web access logs for anomalous traffic patterns indicating credential stuffing or brute-forcing behavior against the specific verification endpoint.
- Monitor webserver logs for high volumes of POST requests to /api/access-tokens/verify-totp originating from a single source IP.
- Implement request rate-limiting on the Planka /api/access-tokens/verify-totp endpoint at the web application firewall (WAF) or reverse proxy level to mitigate brute-force attempts.
- Audit Planka authentication logs for an unusually high number of failed TOTP verification attempts associated with a single user account.
Immediate actions
Deploy WAF rate-limiting for /api/access-tokens/verify-totp
Threat Hunt
Search logs for high frequency POST requests to the verify-totp endpoint
Data: webserver_logs
Detection coverage 1
Detect Excessive TOTP Verification Failures
highDetects potential brute-force attempts against the Planka /api/access-tokens/verify-totp endpoint by identifying a high volume of POST requests resulting in unsuccessful verification.
Detection queries are available on the platform. Get full rules →