Replay Vulnerability in MISP's One-Time Password Authentication Flow
CVE-2026-103651

7.6HIGH

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103651?

MISP is affected by a replay vulnerability in its one-time password (OTP) authentication mechanism, specifically when using HOTP tokens. This flaw allows an attacker with an active session to reuse a consumed HOTP token due to a mismatch in the token verification process. Instead of validating the OTP against the authoritative counter in the database, the system relies on a session-cached counter. If the attacker has already completed the password step and possesses a valid HOTP token, they can exploit this weakness to reauthenticate successfully, effectively undermining the security measures intended to protect user accounts and corrupting the integrity of the HOTP counter, leading to potential unauthorized access and the invalidation of future tokens.

Affected Version(s)

MISP 0 < 2.5.48

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tanguy Snoeck of NCIA
iglocska
Claude Opus 5.5 (1M context)
.