Preconditions:
- The target MISP instance has email OTP login enabled.
- The attacker possesses a valid, unexpired OTP (e.g., via email interception or social engineering).
- The attacker can issue two HTTP POST requests in close temporal proximity.
Impact:
- The one-time-use guarantee of the OTP is violated; a single code can yield two authenticated sessions.
- This weakens the authentication control and may facilitate unauthorized access if the OTP is shared or intercepted.
Affected versions: <2.5.48
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The fix makes OTP consumption atomic by moving the deletion of the OTP from the shared store into the validation condition itself. The return value of the delete operation (1 if the key was actually removed, 0 otherwise) is now part of the success check, so only the request that successfully removes the OTP from the store is permitted to proceed with login. A session-state cleanup call was also added to remove the OTP user reference from the session.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/MISP/MISP/commit/ba95e67d5 |
|
Wed, 07 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Oct 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MISP contains a race condition in the email-based one-time password (OTP) login flow. When two HTTP requests carrying the same valid OTP are submitted concurrently, both can successfully authenticate and establish a session. The root cause is that the OTP value is read from the shared store, validated, and then deleted in separate non-atomic steps, allowing a second in-flight request to read the same value before the first request's deletion takes effect. Preconditions: - The target MISP instance has email OTP login enabled. - The attacker possesses a valid, unexpired OTP (e.g., via email interception or social engineering). - The attacker can issue two HTTP POST requests in close temporal proximity. Impact: - The one-time-use guarantee of the OTP is violated; a single code can yield two authenticated sessions. - This weakens the authentication control and may facilitate unauthorized access if the OTP is shared or intercepted. Affected versions: <2.5.48 | |
| Title | MISP Email OTP Race Condition Allows One-Time Password to Be Consumed by Multiple Concurrent Requests | |
| First Time appeared |
Misp
Misp misp |
|
| Weaknesses | CWE-362 CWE-367 |
|
| CPEs | cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Misp
Misp misp |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CIRCL
Published:
Updated: 2026-10-07T20:28:21.466Z
Reserved: 2026-10-07T15:36:46.122Z
Link: CVE-2026-107276
Updated: 2026-10-07T20:28:17.361Z
Status : Deferred
Published: 2026-10-07T16:17:47.213
Modified: 2026-10-07T21:17:14.903
Link: CVE-2026-107276
No data.
OpenCVE Enrichment
Updated: 2026-10-07T18:30:14Z