Improper Restriction of Excessive Authentication Attempts in GLPI - CVE-2026-49470
Published: July 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass two-factor authentication and take over accounts.
The vulnerability exists due to improper restriction of excessive authentication attempts in the TOTP-based 2FA mechanism when submitting TOTP codes during authentication. A remote attacker can perform brute-force attempts against the 2FA verification process to bypass two-factor authentication and take over accounts.