Two-Factor Authentication Bypass in MISP Instances by MISP
CVE-2026-107180

7.1HIGH

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-107180?

An authentication bypass vulnerability exists in MISP instances where TOTP enrolment is required. Users who have not completed TOTP setup can exploit this flaw to bypass mandatory two-factor authentication by executing non-browser requests, such as AJAX calls or REST API actions. This oversight enables them to maintain full access to the MISP instance without being prompted to enroll in two-factor authentication, undermining the intended security protocols. Once identified, the initial fix addressed AJAX requests, followed by an enhancement to cover all non-browser request types while preserving API key exemptions.

Affected Version(s)

MISP 0 < 2.5.48

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tanguy Snoeck
iglocska
Claude Opus 4.8
Claude Opus 5
.