CVE-2026-32729Disclosure(runtipi / runtipi)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch runtipi runtipi systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enforce any rate limiting, attempt counting, or account lockout mechanism. An attacker who has obtained a user's valid credentials (via phishing, credential stuffing, or data breach) can brute-force the 6-digit TOTP code to completely bypass two-factor authentication. The TOTP verification session persists for 24 hours (default cache TTL), providing an excessive window during which the full 1,000,000-code keyspace (000000–999999) can be exhausted. At practical request rates (~500 req/s), the attack completes in approximately 33 minutes in the worst case. This vulnerability is fixed in 4.8.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-307CWE-799

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • runtipi

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-13); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
runtipi

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-13: 2Mentions · 2026-03-18: 1Patch / Workaround · 2026-03-13: 1Technical Details · 2026-03-13: 2Technical Details · 2026-03-18: 103-1303-18
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-132
Disclosure1Patch1
2026-03-181
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Patch

    CVE-2026-32729 Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enforce any rate limiting, attempt counting, or acc… https://www.cve.org/CVERecord?id=CVE-2026-32729

    Post summary

    The CVE details a missing rate limiting on Runtipi’s TOTP endpoint; version 4.8.1 contains a patch, but no exploit code or active exploitation is reported.

    00010127
    56.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32729 - High Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enforce any rate limiting, attempt counting, or account lockout mechanism. A... https://www.thehackerwire.com/vulnerability/CVE-2026-32729/ https://t.co/7OyKsWWvlo

    Post summary

    CVE-2026-32729 affects Runtipi’s /api/auth/verify-totp endpoint in versions prior to 4.8.1 by lacking rate limiting and account lockout, exposing a brute-force vulnerability. No PoC, exploit, patch, or active exploitation is reported.

    0000042
    138 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-32729 - Runtipi has a TOTP two-factor authentication bypass via unrestricted brute-force on `/api/auth/verify-totp` Intel Report: https://ift.tt/svVn9lk

    Post summary

    The message announces CVE-2026-32729, describing a TOTP two‑factor authentication bypass in Runtipi that allows unrestricted brute‑force on the `/api/auth/verify-totp` endpoint.

    0000030
    340 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appruntipiruntipi---

Explore more