---
id: CVE-2026-107276
title: >-
  MISP contains a race condition in the email-based one-time password (OTP)
  login flow
summary: >-
  MISP contains a race condition in the email-based one-time password (OTP)
  login flow. When two HTTP requests carrying the same valid OTP are submitted
  concurrently, both can successfully authenticate and establish a session. The
  root cau…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N'
cwe:
  - CWE-362
  - CWE-367
vendor: MISP
product: MISP
affected:
  - MISP < 2.5.48
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T16:17:47.340'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107276'
references:
  - url: 'https://github.com/MISP/MISP/commit/ba95e67d5'
    label: 5a6e4751-2f3f-4070-9419-94fb35b644e8
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-07T16:38:22.229Z'
---

## Overview

MISP contains a race condition in the email-based one-time password (OTP) login flow. When two HTTP requests carrying the same valid OTP are submitted concurrently, both can successfully authenticate and establish a session. The root cause is that the OTP value is read from the shared store, validated, and then deleted in separate non-atomic steps, allowing a second in-flight request to read the same value before the first request's deletion takes effect.

Preconditions:

- The target MISP instance has email OTP login enabled.

- The attacker possesses a valid, unexpired OTP (e.g., via email interception or social engineering).

- The attacker can issue two HTTP POST requests in close temporal proximity.

Impact:

- The one-time-use guarantee of the OTP is violated; a single code can yield two authenticated sessions.

- This weakens the authentication control and may facilitate unauthorized access if the OTP is shared or intercepted.

Affected versions: <2.5.48

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
