CVE-2026-33640 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users not associated with an Identity Provider.…
Critical CVSS: 9.1

CVE-2026-33640

Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users not associated with an Identity Provider. Starting in version 0.86.0 and prior to version 1.6.0, Outline does not invalidate OTP codes based on amount or frequency of invalid submissions, rather it relies on the rate limiter to restrict attempts. Consequently, identified bypasses in the rate limiter permit unrestricted OTP code submissions within the codes lifetime. This allows attackers to perform brute force attacks which enable account takeover. Version 1.6.0 fixes the issue.
Vendor
Getoutline
Product
Outline
CWE
CWE-307
Yayın Tarihi
2026-03-26 21:17:07
Güncelleme
2026-03-31 01:42:34
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar