Authentication Bypass Vulnerability in MISP's LdapAuth and LinOTPAuth Plugins
CVE-2026-90961

9.3CRITICAL

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-90961?

The LdapAuth and LinOTPAuth authentication plugins in MISP exhibit a significant authentication bypass vulnerability due to inadequate input validation. These plugins fail to replicate the security measures of CakePHP's FormAuthenticate class, allowing empty and non-string inputs to bypass authentication checks. As a consequence, an attacker familiar with a valid user email in the directory can authenticate without a password, potentially gaining full access to the impersonated user's privileges. This could lead to unauthorized access to critical threat intelligence data. Additionally, newly created user accounts during LDAP login are provisioned with empty passwords, further exacerbating the issue. This vulnerability requires active plugins and prior knowledge of a user email for exploitation.

Affected Version(s)

MISP 0 < 2.5.46

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

elhoim (David André)
iglocska
Claude Opus 5 (1M context)
.