CVE-2024-41276

CRITICAL

Kaiten <= 57.131.12 - Unauthenticated Brute Force Attack via PIN Code Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-41276. PoCs published by artemy-ccrsky.

AI-analyzed exploit summary This repository contains a functional exploit script for CVE-2024-41276, which bypasses authentication in Kaiten by brute-forcing a 6-digit PIN code. The exploit leverages the X-Forwarded-For header to bypass rate limits and automates the process of requesting and guessing PINs within the 5-minute expiration window.

Description

A vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application requires users to input a 6-digit PIN code sent to their email for authorization after entering their login credentials. However, the request limiting mechanism can be easily bypassed, enabling attackers to perform a brute force attack to guess the correct PIN and gain unauthorized access to the application.

Exploits (1)

nomisec WORKING POC 4 stars
by artemy-ccrsky · poc
https://github.com/artemy-ccrsky/CVE-2024-41276

This repository contains a functional exploit script for CVE-2024-41276, which bypasses authentication in Kaiten by brute-forcing a 6-digit PIN code. The exploit leverages the X-Forwarded-For header to bypass rate limits and automates the process of requesting and guessing PINs within the 5-minute expiration window.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Kaiten <= 57.131.12
No auth needed
Prerequisites: Valid username in the target Kaiten instance · Network access to the target domain
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Various Sources
https://kaiten.ru/

Scores

CVSS v3 9.8
EPSS 0.0104
EPSS Percentile 59.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-307
Status published
Published Oct 01, 2024
Tracked Since Feb 18, 2026