CVE-2026-107276: fallo de gravedad media en MISP
MISP Email OTP Race Condition Allows One-Time Password to Be Consumed by Multiple Concurrent Requests
Publicada el
10Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.3
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
MISP contains a race condition in the email-based one-time password (OTP) login flow. When two HTTP requests carrying the same valid OTP are submitted concurrently, both can successfully authenticate and establish a session. The root cause is that the OTP value is read from the shared store, validated, and then deleted in separate non-atomic steps, allowing a second in-flight request to read the same value before the first request's deletion takes effect.
Preconditions:
- The target MISP instance has email OTP login enabled.
- The attacker possesses a valid, unexpired OTP (e.g., via email interception or social engineering).
- The attacker can issue two HTTP POST requests in close temporal proximity.
Impact:
- The one-time-use guarantee of the OTP is violated; a single code can yield two authenticated sessions.
- This weakens the authentication control and may facilitate unauthorized access if the OTP is shared or intercepted.
Affected versions: <2.5.48
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Productos afectados
MISP · MISPCVEs relacionadas — MISP
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-95701MEDIUMMISP Path Traversal via Organization Name in Org-Statistics Logo CheckEPSS 0.8%CVE-2026-44381CRITICALMISP: SQL injection via unvalidated ordering parameters in event and shadow attribute listingsEPSS 0.8%CVE-2026-95698MEDIUMMISP Path Traversal in OrgImgHelper findOrgImage via Crafted Organization NameEPSS 0.7%CVE-2026-39962HIGHLDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variableEPSS 0.7%CVE-2026-106513MEDIUMMISP: Site-Admin Can Repoint Redis Workers to Attacker-Controlled Server via UI/API Configuration ChangeEPSS 0.6%CVE-2026-90961CRITICALMISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String CredentialsEPSS 0.6%