CVE-2026-103655Critical· 9.3▾ MidnightMISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window. The issue exists in the user login flow w…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window.
The issue exists in the user login flow where a TOTP code is verified as a second authentication factor. Because the system did not record whether a given TOTP period had already been consumed, the same code remained valid for its entire time window (typically 30 seconds). An attacker who captures a legitimate code during a user's login could replay it to authenticate a second session as that user.
Preconditions:
The target user has TOTP-based two-factor authentication enabled.
The attacker is in a position to observe or intercept the TOTP code during a legitimate login (e.g., network-level interception, shoulder surfing, or a compromised client).
The replay must occur within the TOTP validity period.
Security impact:
Unauthorized account access by replaying a captured one-time code.
Potential compromise of threat-intelligence data and administrative functions accessible to the targeted user.
Affected versions: <v2.5.48.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-103664Medium· 4.8MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel
CVE-2026-103662Medium· 5.1MISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and disable tag). The affected forms echoed a user-supplied tag name value from the request unescaped i…
CVE-2026-103659High· 7.1MISP contains an authorization bypass in the event flattening feature
CVE-2026-103651High· 7.6MISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token counter. The HOTP verification logic compared the submitted token against a …
CVE-2026-103389Medium· 6.2MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path
CVE-2026-103388Medium· 6.2MISP renders the source field of a Galaxy Cluster as a clickable hyperlink whenever the stored value passes PHP's FILTER_VALIDATE_URL validation