CRITICAL 9.8 CVE-2026-78619 Published 25 Aug 2026

Perl Punk::Plugin::TOTP 2FA Bypass

Worried this affects one of your servers?

A vulnerability in Punk::Plugin::TOTP for Perl allows an attacker with a victim's password and recovery code to bypass two-factor authentication.

The issue lies in the comparison of user identifiers, which can be numerically coerced to zero, allowing an attacker to authenticate as another user.

Reference: CVE-2026-78619 on NVD

← Back to Security News