CVE-2026-94112

CVE-2026-94112 published: mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window. Attackers with stolen credentials can authenticate and reuse a captured passcode against multiple aut...

View full NVD advisory → ← Back to CVE watch