Improper Restriction of Excessive Authentication Attempts in ChurchCRM - #VU142437
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass two-factor authentication.
The vulnerability exists due to improper restriction of excessive authentication attempts in the TOTP verification logic in the API and browser login flows when processing repeated OTP verification requests after a correct password has been supplied. A remote attacker can submit repeated guessed TOTP or recovery codes to bypass two-factor authentication.
Exploitation requires knowledge of the victim\'s password and that the victim has two-factor authentication enabled. Recovery codes are affected through the same verification branch.