CVE-2026-32729 affects Runtipi personal homeserver orchestrator versions prior to 4.8.1, where its /api/auth/verify-totp endpoint lacks critical rate limiting and account lockout mechanisms. This vulnerability allows an attacker with valid user credentials to brute-force a 6-digit TOTP code over the network with low complexity, potentially bypassing two-factor authentication within approximately 33 minutes. Rated with a CVSS score of 8.8 (High), successful exploitation leads to high impact on confidentiality, integrity, and availability of the affected system. While not currently listed on the CISA KEV catalog, it is on the Hot List, indicating its significance, though no public exploit code is available, and it has received limited community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.8.1CPE matchmatch criteria | cpe:2.3:a:runtipi:runtipi:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.