CVE-2026-94112
mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window. Attackers with stolen credentials can authenticate and reuse a captured passcode against multiple authorization attempts for approximately 90 seconds without detection.
- Published Sep 20, 2026
- CVSS 7.6 high
- 0.4% chance of exploitation in the next 30 days (EPSS)
- A fix is available