{"id":"CVE-2026-107276","title":"MISP contains a race condition in the email-based one-time password (OTP) login flow","summary":"MISP contains a race condition in the email-based one-time password (OTP) login flow. When two HTTP requests carrying the same valid OTP are submitted concurrently, both can successfully authenticate and establish a session. The root cau…","severity":"medium","cvss":6.3,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N","cwe":["CWE-362","CWE-367"],"vendor":"MISP","product":"MISP","affected":["MISP < 2.5.48"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T16:17:47.340","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107276","references":[{"url":"https://github.com/MISP/MISP/commit/ba95e67d5","label":"5a6e4751-2f3f-4070-9419-94fb35b644e8"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-07T16:38:22.229Z","slug":"CVE-2026-107276","body":"## Overview\n\nMISP contains a race condition in the email-based one-time password (OTP) login flow. When two HTTP requests carrying the same valid OTP are submitted concurrently, both can successfully authenticate and establish a session. The root cause is that the OTP value is read from the shared store, validated, and then deleted in separate non-atomic steps, allowing a second in-flight request to read the same value before the first request's deletion takes effect.\n\nPreconditions:\n\n- The target MISP instance has email OTP login enabled.\n\n- The attacker possesses a valid, unexpired OTP (e.g., via email interception or social engineering).\n\n- The attacker can issue two HTTP POST requests in close temporal proximity.\n\nImpact:\n\n- The one-time-use guarantee of the OTP is violated; a single code can yield two authenticated sessions.\n\n- This weakens the authentication control and may facilitate unauthorized access if the OTP is shared or intercepted.\n\nAffected versions: <2.5.48\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}