Two-Factor Authentication Bypass in MISP Instances by MISP
CVE-2026-107180
7.1HIGH
What is CVE-2026-107180?
An authentication bypass vulnerability exists in MISP instances where TOTP enrolment is required. Users who have not completed TOTP setup can exploit this flaw to bypass mandatory two-factor authentication by executing non-browser requests, such as AJAX calls or REST API actions. This oversight enables them to maintain full access to the MISP instance without being prompted to enroll in two-factor authentication, undermining the intended security protocols. Once identified, the initial fix addressed AJAX requests, followed by an enhancement to cover all non-browser request types while preserving API key exemptions.
Affected Version(s)
MISP 0 < 2.5.48
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tanguy Snoeck
iglocska
Claude Opus 4.8
Claude Opus 5
