Kaiten 57.131.12 and earlier contains an authentication weakness in its email-delivered six-digit PIN authorization process. The mechanism intended to limit PIN-submission requests can be bypassed, allowing an attacker to brute-force PIN values after supplying login credentials and thereby bypass PIN authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Bash exploit script (CVE-2024-41276.sh) and a README.md describing an authentication bypass vulnerability (CVE-2024-41276) in the Kaiten workflow management system (versions <= 57.131.12). The exploit targets the PIN-based authentication mechanism, which is vulnerable to brute-force attacks due to insufficient rate limiting. The script automates the process of requesting new PINs and brute-forcing the 6-digit code by leveraging the X-Forwarded-For header to bypass rate limits. It uses the ffuf tool with a 6-digit PIN wordlist to submit guesses to the /pin endpoint and checks for successful authentication by parsing ffuf's output. Upon success, it extracts a valid session cookie for further unauthorized access. The README provides usage instructions, details about the vulnerability, affected versions, and mitigation advice. The main exploit file is the Bash script, which is operational and requires the attacker to know a valid username and the target domain.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.