{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/planka-2.2.0-2.2.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:planka:planka:2.2.0:*:*:*:*:*:*:*","cpe:2.3:a:planka:planka:2.2.1:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-105835"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Planka (2.2.0-2.2.1)"],"_cs_severities":["high"],"_cs_tags":["credential-access","vulnerability","web-application"],"_cs_type":"advisory","_cs_vendors":["Planka"],"content_html":"\u003cp\u003ePlanka versions 2.2.0 through 2.2.1 are vulnerable to a brute-force attack targeting the two-factor authentication (2FA) mechanism. The vulnerability exists within the /api/access-tokens/verify-totp endpoint, which fails to implement rate-limiting or account lockout mechanisms for failed TOTP code submissions. If an attacker has obtained a user's password, they can leverage the ten-minute pending token issued by the application to systematically guess six-digit TOTP codes. Given the lack of throttling, an attacker can exhaustively attempt combinations until the correct token is identified, ultimately resulting in unauthorized access to the victim's account. This flaw represents a significant risk for organizations relying on the native 2FA implementation in Planka, as it effectively bypasses the second layer of security.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains a valid username and password through credential harvesting or other initial access methods.\u003c/li\u003e\n\u003cli\u003eAttacker initiates the authentication process against the Planka instance using the compromised credentials.\u003c/li\u003e\n\u003cli\u003eThe server validates the password and returns a ten-minute valid pending token, prompting for the second-factor code.\u003c/li\u003e\n\u003cli\u003eAttacker targets the /api/access-tokens/verify-totp endpoint with high-frequency HTTP POST requests.\u003c/li\u003e\n\u003cli\u003eAttacker iterates through six-digit TOTP code combinations within the ten-minute window allowed by the pending token.\u003c/li\u003e\n\u003cli\u003eThe server fails to enforce rate limits or block the source IP after repeated failed attempts.\u003c/li\u003e\n\u003cli\u003eUpon successfully guessing the correct code, the server returns a full session access token.\u003c/li\u003e\n\u003cli\u003eAttacker uses the acquired access token to gain unauthorized entry to the application.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized actors to bypass 2FA, leading to full account takeover. The impact includes the potential for unauthorized access to project management data, sensitive information exposure, and further lateral movement within the compromised environment. This vulnerability affects all deployments of Planka versions 2.2.0 and 2.2.1.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection engineering teams should monitor web access logs for anomalous traffic patterns indicating credential stuffing or brute-forcing behavior against the specific verification endpoint.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor webserver logs for high volumes of POST requests to /api/access-tokens/verify-totp originating from a single source IP.\u003c/li\u003e\n\u003cli\u003eImplement request rate-limiting on the Planka /api/access-tokens/verify-totp endpoint at the web application firewall (WAF) or reverse proxy level to mitigate brute-force attempts.\u003c/li\u003e\n\u003cli\u003eAudit Planka authentication logs for an unusually high number of failed TOTP verification attempts associated with a single user account.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T16:56:21Z","date_published":"2026-10-06T16:56:21Z","id":"https://feed.craftedsignal.io/briefs/2026-10-planka-totp-brute-force/","summary":"Planka versions 2.2.0 through 2.2.1 contain a vulnerability in the TOTP verification endpoint that lacks rate-limiting, allowing attackers with known user passwords to brute-force two-factor authentication tokens.","title":"Brute-Force Vulnerability in Planka TOTP Authentication","url":"https://feed.craftedsignal.io/briefs/2026-10-planka-totp-brute-force/"}],"language":"en","title":"CraftedSignal Threat Feed - Planka (2.2.0-2.2.1)","version":"https://jsonfeed.org/version/1.1"}