CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-47677

criticalcovered by 1 sourcefirst seen 2026-07-13
Authentication bypass in FacturaScripts: /login?action=two-factor-validation accepts brute-forceable TOTP without password or CSRF protection Summary Core/Controller/Login.php::twoFactorValidationAction() accepts an unauthenticated POST containing only fsNick and fsTwoFactorCode. If the TOTP value matches, the server issues a full fsNick + fsLogkey session cookie pair. The handler: 1. Does not verify the password — the user is not required to have just completed loginAction. 2. Does not call validateFormToken() — no CSRF token is required (every other action handler in the same file does call it). 3. Does not call userHasManyIncidents() before processing — loginAction and changePasswordAction both check this guard *before* doing work; the 2FA handler only writes to the incident list *after* a failure, and the incident list is consulted by loginAction / changePasswordAction but not by the 2FA handler itself. The endpoint therefore has no rate-limiting at all. Combined with TwoFactorManager::VERIFICATION_WINDOW = 8 (google2fa default is 1), 17 distinct six-digit codes are valid simultaneously and each remains valid for ~4 minutes. The expected number of guesses to land a valid code is N ≈ ln(0.5) / ln(1 − 17 / 10⁶) ≈ 40 800 attempts (50% success) On a default LAMP install a single-laptop attacker sustains ~400 RPS from one source IP — a few minutes per account. The vulnerability gives complete account takeover of any 2FA-enabled user to any unauthenticated network attacker who knows the target's nick. Admin nicks are typically public information (admin, the company name, the person's initials). Severity CVSS 4.0 base score: 9.3 — Critical Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N | Metric | Value | Rationale | |---|---|---| | Attack Vector (AV) | Network (N) | One HTTP POST over the public internet. | | Attack Complexity (AC) | Low (L) | No timing, configuration, or environmental conditions. | | Attack Requirements (AT) | None

⚡ Watch CVE-2026-47677

Get an email if CVE-2026-47677 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-47677

CVE.org record

Embed the live status

CVE-2026-47677 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-47677 status](https://www.csirts.com/badge/CVE-2026-47677)](https://www.csirts.com/cve/CVE-2026-47677)