PT-2026-28503 · Outline · Outline
Themisp20
·
Publicado
2026-03-26
·
Atualizado
2026-03-27
·
CVE-2026-33640
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Outline versions 0.86.0 through 1.5.9
Description
Outline is a service that allows for collaborative documentation. It uses an Email OTP login flow for users not associated with an Identity Provider. Versions of Outline between 0.86.0 and 1.5.9 do not invalidate OTP codes based on the number or frequency of invalid submissions, relying instead on a rate limiter to restrict attempts. Identified bypasses in the rate limiter allow attackers to submit OTP codes without restriction within the codes' lifetime. This enables brute force attacks that can lead to account takeover.
Recommendations
Update to version 1.6.0 or later.
Exploit
Correção
Improper Restriction of Excessive Authentication Attempts
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Outline