CVE-2026-57574

Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a vulnerability in Time-based One-Time Password (TOTP) authentication in UserAuthService where insufficient validation of used tokens allows the reuse of a single-use code within its valid time step. If both credentials and a TOTP code are obtained concurrently, an attacker may reuse the code to perform unauthorized actions, potentially leading to account takeover. This issue is fixed in version 2026.6.0.
CVSS

No CVSS.

Configurations

No configuration.

History

10 Jul 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-10 21:16

Updated : 2026-07-13 19:21


NVD link : CVE-2026-57574

Mitre link : CVE-2026-57574

CVE.ORG link : CVE-2026-57574


JSON object : View

Products Affected

No product.

CWE
CWE-294

Authentication Bypass by Capture-replay