NONE · 0

CVE-2026-56450

AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reached the 2FA verification step, such as after successfully completing the passwor...

Vulnerability Description

AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reached the 2FA verification step, such as after successfully completing the password-authentication stage, could submit an unlimited number of OTP guesses. This could enable brute-force guessing of a valid code and bypass the intended second authentication factor, resulting in unauthorized account access. The patch introduces per-user failed-OTP tracking, blocks verification after 30 failed attempts for one hour, clears the counter after a successful OTP verification, and provides administrator recovery actions to purge affected lockouts.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-56450?

CVE-2026-56450 is a documented vulnerability. AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reached the 2FA verification step, such as after successfully completing the passwor...

How severe is CVE-2026-56450?

CVSS scoring is not yet available for CVE-2026-56450. Check NVD for updates.

Is there a patch for CVE-2026-56450?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.