Preconditions:
- The target MISP instance has email OTP login enabled.
- The attacker possesses a valid, unexpired OTP (e.g., via email interception or social engineering).
- The attacker can issue two HTTP POST requests in close temporal proximity.
Impact:
- The one-time-use guarantee of the OTP is violated; a single code can yield two authenticated sessions.
- This weakens the authentication control and may facilitate unauthorized access if the OTP is shared or intercepted.
Affected versions: <2.5.48
Metrics
Affected Vendors & Products
No advisories yet.
Solution
The fix makes OTP consumption atomic by moving the deletion of the OTP from the shared store into the validation condition itself. The return value of the delete operation (1 if the key was actually removed, 0 otherwise) is now part of the success check, so only the request that successfully removes the OTP from the store is permitted to proceed with login. A session-state cleanup call was also added to remove the OTP user reference from the session.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://github.com/MISP/MISP/commit/ba95e67d5 |
|
Wed, 07 Oct 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MISP contains a race condition in the email-based one-time password (OTP) login flow. When two HTTP requests carrying the same valid OTP are submitted concurrently, both can successfully authenticate and establish a session. The root cause is that the OTP value is read from the shared store, validated, and then deleted in separate non-atomic steps, allowing a second in-flight request to read the same value before the first request's deletion takes effect. Preconditions: - The target MISP instance has email OTP login enabled. - The attacker possesses a valid, unexpired OTP (e.g., via email interception or social engineering). - The attacker can issue two HTTP POST requests in close temporal proximity. Impact: - The one-time-use guarantee of the OTP is violated; a single code can yield two authenticated sessions. - This weakens the authentication control and may facilitate unauthorized access if the OTP is shared or intercepted. Affected versions: <2.5.48 | |
| Title | MISP Email OTP Race Condition Allows One-Time Password to Be Consumed by Multiple Concurrent Requests | |
| First Time appeared |
Misp
Misp misp |
|
| Weaknesses | CWE-362 CWE-367 |
|
| CPEs | cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Misp
Misp misp |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CIRCL
Published:
Updated: 2026-10-07T15:36:49.564Z
Reserved: 2026-10-07T15:36:46.122Z
Link: CVE-2026-107276
No data.
Status : Deferred
Published: 2026-10-07T16:17:47.213
Modified: 2026-10-07T16:17:47.340
Link: CVE-2026-107276
No data.
OpenCVE Enrichment
No data.