CVE-2026-107276Medium· 6.3▾ SunlitMISP contains a race condition in the email-based one-time password (OTP) login flow. When two HTTP requests carrying the same valid OTP are submitted concurrently, both can successfully authenticate and establish a session. The root cau…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
MISP contains a race condition in the email-based one-time password (OTP) login flow. When two HTTP requests carrying the same valid OTP are submitted concurrently, both can successfully authenticate and establish a session. The root cause is that the OTP value is read from the shared store, validated, and then deleted in separate non-atomic steps, allowing a second in-flight request to read the same value before the first request's deletion takes effect.
Preconditions:
The target MISP instance has email OTP login enabled.
The attacker possesses a valid, unexpired OTP (e.g., via email interception or social engineering).
The attacker can issue two HTTP POST requests in close temporal proximity.
Impact:
The one-time-use guarantee of the OTP is violated; a single code can yield two authenticated sessions.
This weakens the authentication control and may facilitate unauthorized access if the OTP is shared or intercepted.
Affected versions: <2.5.48
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-103651High· 7.6MISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token counter. The HOTP verification logic compared the submitted token against a …
CVE-2026-107278Medium· 5.3MISP contains a validation flaw in its object synchronization logic
CVE-2026-107180High· 7.1On MISP instances configured to require TOTP enrolment (Security.otp_required), the enforcement of the mandatory two-factor authentication setup applied only to standard browser requests
CVE-2026-107175Medium· 5.3MISP contains a defect in its event save workflow that prevents the correlation engine from recalculating correlations when an event's distribution level or sharing group is modified. When a user edits an existing event and changes its …
CVE-2026-106513Medium· 6.9MISP exposes critical infrastructure settings—specifically the Redis host addresses used by the core application, the ZeroMQ plugin, and the SimpleBackgroundJobs plugin—through its web UI and API to site-admin users
CVE-2026-104914Medium· 5.3MISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints. When a user queries for soft-deleted attributes (e.g., via the deleted-attributes search or the paginated attribute l…