---
id: CVE-2026-94112
title: >-
  mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after
  use, allowing attackers to replay captured codes within the acceptance window
summary: >-
  mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after
  use, allowing attackers to replay captured codes within the acceptance window.
  Attackers with stolen credentials can authenticate and reuse a captured
  passcode …
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N'
cwe:
  - CWE-294
vendor: mayswind
product: ezBookkeeping
affected:
  - ezBookkeeping < 2.0.0
published: '2026-09-20'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:08:55.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94112'
references:
  - url: >-
      https://github.com/mayswind/ezbookkeeping/commit/3dd6286d7a3ab0f980a6d36339b9c9c4df9467e4
    label: disclosure@vulncheck.com
  - url: 'https://github.com/mayswind/ezbookkeeping/releases/tag/v2.0.0'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/mayswind/ezbookkeeping/security/advisories/GHSA-p6qr-48g6-97q3
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/mayswind-ezbookkeeping-before-2.0.0-totp-replay-attack
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00393
epssPercentile: 0.3064
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-21T16:23:05.246566Z'
ingestedAt: '2026-09-20T12:21:05.903Z'
---

## Overview

mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window. Attackers with stolen credentials can authenticate and reuse a captured passcode against multiple authorization attempts for approximately 90 seconds without detection.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
