PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-46473 TCHATZI CVE debrief

CVE-2026-46473 describes a high-severity weakness in Authen::TOTP versions before 0.1.1: secrets were generated with Perl’s built-in rand function. Because rand is predictable and not appropriate for security-sensitive secret generation, affected deployments may produce weak TOTP secrets. The issue was published on 2026-05-21 and the source record points to a fix in the 0.1.1 release.

Vendor
TCHATZI
Product
Authen::TOTP
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-21
Original CVE updated
2026-07-23
Advisory published
2026-05-21
Advisory updated
2026-07-23

Who should care

Administrators and developers using Authen::TOTP before 0.1.1, especially anyone relying on generated secrets for authentication workflows. Security teams should treat this as a credential-strength issue affecting OTP setup and provisioning.

Technical summary

The NVD record classifies the issue as CVE-2026-46473 with CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N and CWE-331. The vulnerability stems from generating secrets using Perl rand instead of a cryptographically secure source. The supplied references include a patch commit and the Authen::TOTP 0.1.1 changes page, indicating remediation in that release.

Defensive priority

High. Weak secret generation can undermine the security of newly provisioned TOTP secrets, so affected versions should be updated promptly and any secrets created by vulnerable versions should be treated as potentially compromised or low-entropy.

Recommended defensive actions

  • Upgrade Authen::TOTP to version 0.1.1 or later.
  • Audit any deployments that generated TOTP secrets before the fix and re-issue secrets where appropriate.
  • Review application code and packaging to confirm no older Authen::TOTP release remains in use.
  • Validate that secret generation uses a cryptographically secure random source, not Perl rand.
  • Check authentication logs and user support workflows for any indication of weak or reused provisioning secrets.

Evidence notes

This debrief is based only on the supplied NVD CVE record and the referenced upstream materials. The NVD metadata states the weakness as CWE-331 and describes the issue as secrets generated using Perl’s built-in rand function. The referenced upstream materials are a patch commit and the 0.1.1 changes entry, which together support the remediation version. Vendor/product naming in the supplied corpus is inconsistent, so the technical finding is attributed to Authen::TOTP as described in the CVE text and references.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-46473 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-46473

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-46473 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46473

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/tchatzi/Authen-TOTP/commit/d04f30cc6538d77fc6b6d550da450cf3017b8561.patch

    9b29abf9-4ab0-4765-b253-1875cd9b441e

  • Source reference

    Unverified legacy reference

    URL: https://metacpan.org/release/TCHATZI/Authen-TOTP-0.1.1/changes

    9b29abf9-4ab0-4765-b253-1875cd9b441e

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.