<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:planka:planka:2.2.0:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aplankaplanka2.2.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 16:56:21 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aplankaplanka2.2.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Brute-Force Vulnerability in Planka TOTP Authentication</title><link>https://feed.craftedsignal.io/briefs/2026-10-planka-totp-brute-force/</link><pubDate>Tue, 06 Oct 2026 16:56:21 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-planka-totp-brute-force/</guid><description>Planka versions 2.2.0 through 2.2.1 contain a vulnerability in the TOTP verification endpoint that lacks rate-limiting, allowing attackers with known user passwords to brute-force two-factor authentication tokens.</description><content:encoded><![CDATA[<p>Planka versions 2.2.0 through 2.2.1 are vulnerable to a brute-force attack targeting the two-factor authentication (2FA) mechanism. The vulnerability exists within the /api/access-tokens/verify-totp endpoint, which fails to implement rate-limiting or account lockout mechanisms for failed TOTP code submissions. If an attacker has obtained a user's password, they can leverage the ten-minute pending token issued by the application to systematically guess six-digit TOTP codes. Given the lack of throttling, an attacker can exhaustively attempt combinations until the correct token is identified, ultimately resulting in unauthorized access to the victim's account. This flaw represents a significant risk for organizations relying on the native 2FA implementation in Planka, as it effectively bypasses the second layer of security.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker obtains a valid username and password through credential harvesting or other initial access methods.</li>
<li>Attacker initiates the authentication process against the Planka instance using the compromised credentials.</li>
<li>The server validates the password and returns a ten-minute valid pending token, prompting for the second-factor code.</li>
<li>Attacker targets the /api/access-tokens/verify-totp endpoint with high-frequency HTTP POST requests.</li>
<li>Attacker iterates through six-digit TOTP code combinations within the ten-minute window allowed by the pending token.</li>
<li>The server fails to enforce rate limits or block the source IP after repeated failed attempts.</li>
<li>Upon successfully guessing the correct code, the server returns a full session access token.</li>
<li>Attacker uses the acquired access token to gain unauthorized entry to the application.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthorized actors to bypass 2FA, leading to full account takeover. The impact includes the potential for unauthorized access to project management data, sensitive information exposure, and further lateral movement within the compromised environment. This vulnerability affects all deployments of Planka versions 2.2.0 and 2.2.1.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Detection engineering teams should monitor web access logs for anomalous traffic patterns indicating credential stuffing or brute-forcing behavior against the specific verification endpoint.</p>
<ul>
<li>Monitor webserver logs for high volumes of POST requests to /api/access-tokens/verify-totp originating from a single source IP.</li>
<li>Implement request rate-limiting on the Planka /api/access-tokens/verify-totp endpoint at the web application firewall (WAF) or reverse proxy level to mitigate brute-force attempts.</li>
<li>Audit Planka authentication logs for an unusually high number of failed TOTP verification attempts associated with a single user account.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>credential-access</category><category>vulnerability</category><category>web-application</category></item></channel></rss>