{"api_version":"1","generated_at":"2026-10-11T05:15:07+00:00","cve":"CVE-2026-94206","urls":{"html":"https://cve.report/CVE-2026-94206","api":"https://cve.report/api/cve/CVE-2026-94206.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-94206","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-94206"},"summary":{"title":"Cloak PBKDF2 field ignores the configured iteration count and runs only :size rounds","description":"Use of Password Hash With Insufficient Computational Effort vulnerability in danielberkompas cloak_ecto and danielberkompas cloak allows an attacker who holds the hashed values and the configured secret to brute-force low-entropy plaintexts much faster than configured.\n\nThe dump/1 callback that Cloak.Ecto.PBKDF2 (Cloak.Fields.PBKDF2 in cloak before the Ecto code moved to cloak_ecto) injects into a field module calls :pbkdf2.pbkdf2/4 with config[:size] in the iteration-count position. The :iterations setting is validated but never used. With the cloak_ecto defaults (iterations: 600_000, size: 32) each hash runs 32 PBKDF2 rounds instead of 600,000, so offline guessing of values such as email addresses costs about 18,750 times less than configured.\n\nThis issue affects cloak_ecto: from 1.0.0-alpha.0 onward; cloak: from 0.7.0 before 1.0.0-alpha.0.","state":"PUBLISHED","assigner":"EEF","published_at":"2026-10-06 09:17:56","updated_at":"2026-10-06 15:03:59"},"problem_types":["CWE-916","CWE-916 CWE-916 Use of Password Hash With Insufficient Computational Effort"],"metrics":[{"version":"4.0","source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","type":"Secondary","score":"6.3","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"6.3","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":6.3,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"}}],"references":[{"url":"https://github.com/danielberkompas/cloak_ecto/commit/a8fa1642b02f1c445a1ee8794c9095eb0921f8f3","name":"https://github.com/danielberkompas/cloak_ecto/commit/a8fa1642b02f1c445a1ee8794c9095eb0921f8f3","refsource":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://cna.erlef.org/cves/CVE-2026-94206.html","name":"https://cna.erlef.org/cves/CVE-2026-94206.html","refsource":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-94206","name":"https://osv.dev/vulnerability/EEF-CVE-2026-94206","refsource":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/danielberkompas/cloak/commit/8699e6417a162c39d9f0ef63511bd23d3f38d1d2","name":"https://github.com/danielberkompas/cloak/commit/8699e6417a162c39d9f0ef63511bd23d3f38d1d2","refsource":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/danielberkompas/cloak/commit/681c9702b7cd9afe0e5a840751ab009f550c69a9","name":"https://github.com/danielberkompas/cloak/commit/681c9702b7cd9afe0e5a840751ab009f550c69a9","refsource":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-94206","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94206","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"danielberkompas","product":"cloak_ecto","version":"affected 1.0.0-alpha.0 * semver","platforms":[]},{"source":"CNA","vendor":"danielberkompas","product":"cloak_ecto","version":"affected a8fa1642b02f1c445a1ee8794c9095eb0921f8f3 * git","platforms":[]},{"source":"CNA","vendor":"danielberkompas","product":"cloak","version":"affected 0.7.0 1.0.0-alpha.0 semver","platforms":[]},{"source":"CNA","vendor":"danielberkompas","product":"cloak","version":"affected 8699e6417a162c39d9f0ef63511bd23d3f38d1d2 681c9702b7cd9afe0e5a840751ab009f550c69a9 git","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[{"source":"CNA","title":"","value":"Override dump/1 in the field module that uses Cloak.Ecto.PBKDF2, so that it calls :pbkdf2.pbkdf2/5 with the configured :iterations and :size. Then recompute all stored hashes, because the existing values no longer match.","time":"","lang":"en"}],"exploits":[],"credits":[{"source":"CNA","value":"Peter Ullrich","lang":"en"},{"source":"CNA","value":"Peter Ullrich","lang":"en"},{"source":"CNA","value":"Jonatan Männchen / EEF","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"94206","cve":"CVE-2026-94206","epss":"0.002560000","percentile":"0.157240000","score_date":"2026-10-06","updated_at":"2026-10-07 00:14:54"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-94206","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-10-06T11:34:00.942993Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-06T11:36:25.466Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://repo.hex.pm","cpes":["cpe:2.3:a:danielberkompas:cloak_ecto:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","modules":["'Elixir.Cloak.Ecto.PBKDF2'"],"packageName":"cloak_ecto","packageURL":"pkg:hex/cloak_ecto","product":"cloak_ecto","programFiles":["lib/cloak_ecto/types/pbkdf2.ex"],"repo":"https://github.com/danielberkompas/cloak_ecto","vendor":"danielberkompas","versions":[{"lessThan":"*","status":"affected","version":"1.0.0-alpha.0","versionType":"semver"}]},{"collectionURL":"https://github.com","cpes":["cpe:2.3:a:danielberkompas:cloak_ecto:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","modules":["'Elixir.Cloak.Ecto.PBKDF2'"],"packageName":"danielberkompas/cloak_ecto","packageURL":"pkg:github/danielberkompas/cloak_ecto","product":"cloak_ecto","programFiles":["lib/cloak_ecto/types/pbkdf2.ex"],"repo":"https://github.com/danielberkompas/cloak_ecto","vendor":"danielberkompas","versions":[{"lessThan":"*","status":"affected","version":"a8fa1642b02f1c445a1ee8794c9095eb0921f8f3","versionType":"git"}]},{"collectionURL":"https://repo.hex.pm","cpes":["cpe:2.3:a:danielberkompas:cloak:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","modules":["'Elixir.Cloak.Fields.PBKDF2'"],"packageName":"cloak","packageURL":"pkg:hex/cloak","product":"cloak","programFiles":["lib/cloak/fields/pbkdf2.ex"],"repo":"https://github.com/danielberkompas/cloak","vendor":"danielberkompas","versions":[{"lessThan":"1.0.0-alpha.0","status":"affected","version":"0.7.0","versionType":"semver"}]},{"collectionURL":"https://github.com","cpes":["cpe:2.3:a:danielberkompas:cloak:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","modules":["'Elixir.Cloak.Fields.PBKDF2'"],"packageName":"danielberkompas/cloak","packageURL":"pkg:github/danielberkompas/cloak","product":"cloak","programFiles":["lib/cloak/fields/pbkdf2.ex"],"repo":"https://github.com/danielberkompas/cloak","vendor":"danielberkompas","versions":[{"lessThan":"681c9702b7cd9afe0e5a840751ab009f550c69a9","status":"affected","version":"8699e6417a162c39d9f0ef63511bd23d3f38d1d2","versionType":"git"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:danielberkompas:cloak_ecto:*:*:*:*:*:*:*:*","versionStartIncluding":"1.0.0-alpha.0","vulnerable":true},{"criteria":"cpe:2.3:a:danielberkompas:cloak:*:*:*:*:*:*:*:*","versionEndExcluding":"1.0.0-alpha.0","versionStartIncluding":"0.7.0","vulnerable":true}],"negate":false,"operator":"OR"}],"operator":"AND"}],"credits":[{"lang":"en","type":"finder","value":"Peter Ullrich"},{"lang":"en","type":"reporter","value":"Peter Ullrich"},{"lang":"en","type":"coordinator","value":"Jonatan Männchen / EEF"}],"dateAssigned":"2026-10-06T08:35:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Use of Password Hash With Insufficient Computational Effort vulnerability in danielberkompas cloak_ecto and danielberkompas cloak allows an attacker who holds the hashed values and the configured secret to brute-force low-entropy plaintexts much faster than configured.</p>\n<p>The <code>dump/1</code> callback that <code>Cloak.Ecto.PBKDF2</code> (<code>Cloak.Fields.PBKDF2</code> in cloak before the Ecto code moved to cloak_ecto) injects into a field module calls <code>:pbkdf2.pbkdf2/4</code> with <code>config[:size]</code> in the iteration-count position. The <code>:iterations</code> setting is validated but never used. With the cloak_ecto defaults (<code>iterations: 600_000</code>, <code>size: 32</code>) each hash runs 32 PBKDF2 rounds instead of 600,000, so offline guessing of values such as email addresses costs about 18,750 times less than configured.</p>\n<p>This issue affects cloak_ecto: from 1.0.0-alpha.0 onward; cloak: from 0.7.0 before 1.0.0-alpha.0.</p>"},{"base64":false,"type":"text/markdown","value":"Use of Password Hash With Insufficient Computational Effort vulnerability in danielberkompas cloak_ecto and danielberkompas cloak allows an attacker who holds the hashed values and the configured secret to brute-force low-entropy plaintexts much faster than configured.\n\nThe `dump/1` callback that `Cloak.Ecto.PBKDF2` (`Cloak.Fields.PBKDF2` in cloak before the Ecto code moved to cloak_ecto) injects into a field module calls `:pbkdf2.pbkdf2/4` with `config[:size]` in the iteration-count position. The `:iterations` setting is validated but never used. With the cloak_ecto defaults (`iterations: 600_000`, `size: 32`) each hash runs 32 PBKDF2 rounds instead of 600,000, so offline guessing of values such as email addresses costs about 18,750 times less than configured.\n\nThis issue affects cloak_ecto: from 1.0.0-alpha.0 onward; cloak: from 0.7.0 before 1.0.0-alpha.0."}],"value":"Use of Password Hash With Insufficient Computational Effort vulnerability in danielberkompas cloak_ecto and danielberkompas cloak allows an attacker who holds the hashed values and the configured secret to brute-force low-entropy plaintexts much faster than configured.\n\nThe dump/1 callback that Cloak.Ecto.PBKDF2 (Cloak.Fields.PBKDF2 in cloak before the Ecto code moved to cloak_ecto) injects into a field module calls :pbkdf2.pbkdf2/4 with config[:size] in the iteration-count position. The :iterations setting is validated but never used. With the cloak_ecto defaults (iterations: 600_000, size: 32) each hash runs 32 PBKDF2 rounds instead of 600,000, so offline guessing of values such as email addresses costs about 18,750 times less than configured.\n\nThis issue affects cloak_ecto: from 1.0.0-alpha.0 onward; cloak: from 0.7.0 before 1.0.0-alpha.0."}],"impacts":[{"capecId":"CAPEC-55","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>An attacker who obtains a database dump and the PBKDF2 secret can recover hashed values with low entropy, such as email addresses, by offline guessing at a cost far below what the configuration promises.</p>"},{"base64":false,"type":"text/markdown","value":"An attacker who obtains a database dump and the PBKDF2 secret can recover hashed values with low entropy, such as email addresses, by offline guessing at a cost far below what the configuration promises."}],"value":"An attacker who obtains a database dump and the PBKDF2 secret can recover hashed values with low entropy, such as email addresses, by offline guessing at a cost far below what the configuration promises."}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":6.3,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-916","description":"CWE-916 Use of Password Hash With Insufficient Computational Effort","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-06T08:38:04.584Z","orgId":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","shortName":"EEF"},"references":[{"name":"EEF CNA record for CVE-2026-94206","tags":["related","third-party-advisory"],"url":"https://cna.erlef.org/cves/CVE-2026-94206.html"},{"name":"OSV record EEF-CVE-2026-94206","tags":["related"],"url":"https://osv.dev/vulnerability/EEF-CVE-2026-94206"},{"name":"Introducing commit a8fa164 in danielberkompas/cloak_ecto","tags":["related"],"url":"https://github.com/danielberkompas/cloak_ecto/commit/a8fa1642b02f1c445a1ee8794c9095eb0921f8f3"},{"name":"Introducing commit 8699e64 in danielberkompas/cloak","tags":["related"],"url":"https://github.com/danielberkompas/cloak/commit/8699e6417a162c39d9f0ef63511bd23d3f38d1d2"},{"name":"Fix commit 681c970 in danielberkompas/cloak","tags":["patch"],"url":"https://github.com/danielberkompas/cloak/commit/681c9702b7cd9afe0e5a840751ab009f550c69a9"}],"source":{"discovery":"EXTERNAL"},"title":"Cloak PBKDF2 field ignores the configured iteration count and runs only :size rounds","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Override <code>dump/1</code> in the field module that uses <code>Cloak.Ecto.PBKDF2</code>, so that it calls <code>:pbkdf2.pbkdf2/5</code> with the configured <code>:iterations</code> and <code>:size</code>. Then recompute all stored hashes, because the existing values no longer match.</p>"},{"base64":false,"type":"text/markdown","value":"Override `dump/1` in the field module that uses `Cloak.Ecto.PBKDF2`, so that it calls `:pbkdf2.pbkdf2/5` with the configured `:iterations` and `:size`. Then recompute all stored hashes, because the existing values no longer match."}],"value":"Override dump/1 in the field module that uses Cloak.Ecto.PBKDF2, so that it calls :pbkdf2.pbkdf2/5 with the configured :iterations and :size. Then recompute all stored hashes, because the existing values no longer match."}],"x_proofOfConcept":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<ol>\n<li>Define a field module with <code>use Cloak.Ecto.PBKDF2</code> and configure only a <code>:secret</code>, so that the defaults <code>iterations: 600_000</code> and <code>size: 32</code> apply.</li>\n<li>Call <code>dump/1</code> on a value.</li>\n<li>Compare the result with <code>:pbkdf2.pbkdf2({:hmac, :sha256}, value, secret, 32)</code> and with the same call at 600,000 rounds. It matches the 32-round hash, not the 600,000-round hash, and returns in microseconds instead of about one second.</li>\n</ol>"},{"base64":false,"type":"text/markdown","value":"1. Define a field module with `use Cloak.Ecto.PBKDF2` and configure only a `:secret`, so that the defaults `iterations: 600_000` and `size: 32` apply.\n2. Call `dump/1` on a value.\n3. Compare the result with `:pbkdf2.pbkdf2({:hmac, :sha256}, value, secret, 32)` and with the same call at 600,000 rounds. It matches the 32-round hash, not the 600,000-round hash, and returns in microseconds instead of about one second."}],"value":"* Define a field module with use Cloak.Ecto.PBKDF2 and configure only a :secret, so that the defaults iterations: 600_000 and size: 32 apply.\n* Call dump/1 on a value.\n* Compare the result with :pbkdf2.pbkdf2({:hmac, :sha256}, value, secret, 32) and with the same call at 600,000 rounds. It matches the 32-round hash, not the 600,000-round hash, and returns in microseconds instead of about one second."}]}},"cveMetadata":{"assignerOrgId":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","assignerShortName":"EEF","cveId":"CVE-2026-94206","datePublished":"2026-10-06T08:38:04.584Z","dateReserved":"2026-09-24T09:30:02.102Z","dateUpdated":"2026-10-06T11:36:25.466Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-06 09:17:56","lastModifiedDate":"2026-10-06 15:03:59","problem_types":["CWE-916","CWE-916 CWE-916 Use of Password Hash With Insufficient Computational Effort"],"metrics":{"cvssMetricV40":[{"source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-06T11:34:00.942993Z","id":"CVE-2026-94206","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"94206","Ordinal":"1","Title":"Cloak PBKDF2 field ignores the configured iteration count and ru","CVE":"CVE-2026-94206","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"94206","Ordinal":"1","NoteData":"Use of Password Hash With Insufficient Computational Effort vulnerability in danielberkompas cloak_ecto and danielberkompas cloak allows an attacker who holds the hashed values and the configured secret to brute-force low-entropy plaintexts much faster than configured.\n\nThe dump/1 callback that Cloak.Ecto.PBKDF2 (Cloak.Fields.PBKDF2 in cloak before the Ecto code moved to cloak_ecto) injects into a field module calls :pbkdf2.pbkdf2/4 with config[:size] in the iteration-count position. The :iterations setting is validated but never used. With the cloak_ecto defaults (iterations: 600_000, size: 32) each hash runs 32 PBKDF2 rounds instead of 600,000, so offline guessing of values such as email addresses costs about 18,750 times less than configured.\n\nThis issue affects cloak_ecto: from 1.0.0-alpha.0 onward; cloak: from 0.7.0 before 1.0.0-alpha.0.","Type":"Description","Title":"Cloak PBKDF2 field ignores the configured iteration count and ru"}]}}}