External risk intelligence

PLANKA TOTP Brute Force Vulnerability in Access Token Verification

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-105835

The vulnerability exists in an API endpoint used for authentication. Planka is a web-based project management application that is typically deployed as a public-facing web service, making its authentication and API endpoints, including those handling 2FA verification, commonly accessible from the internet.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects web-based project management tools, specifically an authentication endpoint that allows attackers to repeatedly guess two-factor authentication codes. If an attacker already has a user's password, they could potentially bypass this security layer to gain unauthorized access. The main concern is confirming if this type of system is in use and exposed.

  • A system flaw lets attackers guess security codes.
  • This could let attackers bypass two-factor authentication.
  • Confirm if this system is in use and exposed.

Attack Path

How an attacker could exploit the issue

An attacker who already knows a user's password can repeatedly guess Time-based One-Time Password (TOTP) codes submitted to an API endpoint. This vulnerability allows for brute-forcing the six-digit codes within a ten-minute window, potentially granting the attacker full access to a user's account by obtaining a valid access token.

  • Entry condition: Attacker knows user's password.
  • Trigger point: Submitting incorrect TOTP codes to API endpoint.
  • Resulting risk: Account takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to bypass two-factor authentication when a user's password is known. If successful, an attacker could gain full access to a user's account by guessing the six-digit TOTP code within a ten-minute window.

  • User account access.
  • Brute force of authentication codes.
  • Unauthorized access to account data.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in PLANKA's TOTP verification endpoint allows for brute-forcing authentication codes. The primary responsibility likely falls to the application or platform team managing the PLANKA instance, in coordination with security and network teams to assess and mitigate exposure. The first practical step is to identify all PLANKA deployments, confirm their internet reachability and business criticality, and then prioritize remediation based on risk.

  • Application owners and platform teams should lead remediation.
  • Verify internet-facing PLANKA instances first.
  • Plan maintenance for risk-based patching or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Planka?

Planka is an open-source, web-based project management tool modeled after platforms like Trello. Teams use it to organize tasks, track progress, and manage workflows visually using boards and cards. Because it manages sensitive project data and user accounts, it includes authentication features like two-factor authentication to secure access to these collaborative spaces.

How does CVE-2026-105835 work?

This vulnerability is classified as CWE-307, which involves improper restriction of excessive authentication attempts. In the affected Planka versions, the system fails to limit how many times a user can submit incorrect two-factor authentication (TOTP) codes. This allows an attacker to repeatedly guess the six-digit code until they eventually get it right, bypassing the extra layer of security intended to protect the account.

Can anyone trigger this authentication bypass?

No. The attack is not possible for just anyone; it requires the attacker to already know the user's password. Once the password is known, the attacker uses the temporary ten-minute pending token generated by the system to submit repeated, incorrect guesses for the second-factor code. If the attacker does not have the password, they cannot initiate the specific authentication flow required to brute-force the TOTP codes.

Is my Planka instance at risk?

Halo Surface Signal indicates that Planka is commonly deployed as a public-facing web service, making its API endpoints—including those used for 2FA—frequently accessible from the internet. If your instance is reachable over the internet, it is more exposed to this type of remote brute-force attempt compared to an instance restricted to an internal, private network.

What should I do if I run Planka?

Begin by creating an inventory of all Planka deployments within your environment to identify which instances are currently running the affected versions. Prioritize those that are accessible from the internet for immediate attention. Work with your platform or security teams to plan maintenance, confirm the scope of usage, and apply the necessary updates or mitigations to restrict unauthorized authentication attempts.

References