Replay Vulnerability in MISP's One-Time Password Authentication Flow
CVE-2026-103651
What is CVE-2026-103651?
MISP is affected by a replay vulnerability in its one-time password (OTP) authentication mechanism, specifically when using HOTP tokens. This flaw allows an attacker with an active session to reuse a consumed HOTP token due to a mismatch in the token verification process. Instead of validating the OTP against the authoritative counter in the database, the system relies on a session-cached counter. If the attacker has already completed the password step and possesses a valid HOTP token, they can exploit this weakness to reauthenticate successfully, effectively undermining the security measures intended to protect user accounts and corrupting the integrity of the HOTP counter, leading to potential unauthorized access and the invalidation of future tokens.
Affected Version(s)
MISP 0 < 2.5.48
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
