PT-2026-28503 · Outline · Outline

Themisp20

·

Published

2026-03-26

·

Updated

2026-03-27

·

CVE-2026-33640

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Outline versions 0.86.0 through 1.5.9
Description Outline is a service that allows for collaborative documentation. It uses an Email OTP login flow for users not associated with an Identity Provider. Versions of Outline between 0.86.0 and 1.5.9 do not invalidate OTP codes based on the number or frequency of invalid submissions, relying instead on a rate limiter to restrict attempts. Identified bypasses in the rate limiter allow attackers to submit OTP codes without restriction within the codes' lifetime. This enables brute force attacks that can lead to account takeover.
Recommendations Update to version 1.6.0 or later.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33640
GHSA-CWHC-53HW-QQX6

Affected Products

Outline