CVE-2026-103651High· 7.6▾ TwilightMISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token counter. The HOTP verification logic compared the submitted token against a …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
MISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token counter.
The HOTP verification logic compared the submitted token against a counter value that was cached in the user's session at the time the password was entered, rather than against the authoritative counter stored in the database. Because the session-cached counter is not updated after a token is successfully consumed, an attacker who holds a valid session (password already submitted) can reuse a previously burned HOTP token. The stale cached counter still matches the replayed token, granting a second successful authentication and effectively rewinding the counter state.
Preconditions:
The target user has HOTP (paper token) second-factor authentication enabled.
The attacker possesses a valid session in which the password step has already been completed (the OTP step is pending).
The attacker has access to at least one HOTP token value (e.g., a paper token list).
Security impact:
Bypass of the second authentication factor, allowing unauthorized access to a user's MISP account.
Corruption of the HOTP counter state, potentially invalidating subsequent legitimate tokens or enabling further replays.
Affected versions: <2.5.48.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-90961Critical· 9.3The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability
CVE-2022-29534High· 7.5An issue was discovered in MISP before 2.4.158
CVE-2026-103664Medium· 4.8MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel
CVE-2026-103662Medium· 5.1MISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and disable tag). The affected forms echoed a user-supplied tag name value from the request unescaped i…
CVE-2026-103659High· 7.1MISP contains an authorization bypass in the event flattening feature
CVE-2026-103655Critical· 9.3MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window. The issue exists in the user login flow w…