PT-2026-83450 · Rodauth · Rodauth

·

CVE-2026-82470

·

Published

2026-08-29

·

Updated

2026-08-29

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Rodauth versions prior to 2.47.0
Description The otp feature fails to track the timestamp of the last accepted code. This allows an attacker who observes a valid Time-based One-Time Password (TOTP) to replay that code within the drift window, enabling them to bypass the second authentication factor.
Recommendations Update to version 2.47.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82470
GHSA-HHVG-6QMV-58VC

Affected Products

Rodauth