๐Ÿ” CVE Alert

CVE-2026-56450

UNKNOWN 0.0

AIL Framework - Missing Rate Limiting Enables Brute-Force Attacks Against Two-Factor Authentication Codes

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reached the 2FA verification step, such as after successfully completing the password-authentication stage, could submit an unlimited number of OTP guesses. This could enable brute-force guessing of a valid code and bypass the intended second authentication factor, resulting in unauthorized account access. The patch introduces per-user failed-OTP tracking, blocks verification after 30 failed attempts for one hour, clears the counter after a successful OTP verification, and provides administrator recovery actions to purge affected lockouts.

CWE CWE-307
Vendor ail project
Product ail framework
Published Jun 22, 2026
Last Updated Jun 22, 2026
Stay Ahead of the Next One

Get instant alerts for ail project ail framework

Be the first to know when new unknown vulnerabilities affecting ail project ail framework are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

ail project / ail framework
0 โ‰ค 6.8.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ail-project/ail-framework/commit/d3a394fe68fd5aeee86f3a3c91d4a0350f91e974

Credits

Aurelien Thirion Stephen O