Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-103651— MISP HOTP Token Replay via Stale Session-Cached Counter Allows Second-Factor Authentication Bypass

Quick assessment

Affected
MISP MISP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MISP 在其一次性密码(OTP)认证流程中存在一个漏洞,该漏洞允许攻击者重放已使用的 HOTP(纸质令牌)并回退令牌计数器。 HOTP 验证逻辑将提交的令牌与用户在输入密码时缓存于会话中的计数器值进行比较,而不是与数据库中存储的权威计数器进行比较。由于在令牌成功消费后,会话中缓存的计数器并未更新,因此持有有效会话(即已完成密码输入步骤)的攻击者可以重用之前已“烧毁”的 HOTP 令牌。过期的缓存计数器仍能与重放的令牌匹配,从而允许第二次成功认证,并实质上回退了计数器的状态。 前提条件: 目标用户已启用 HOTP(

CVSS 7.6 · High EPSS 0.20% · P8

Possible ATT&CK Techniques 1 AI

T1556.002 · Password Filter DLL

Affected Version Matrix 1

VendorProduct Version RangeStatus
MISP MISP < 2.5.48 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-103651

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MISP HOTP Token Replay via Stale Session-Cached Counter Allows Second-Factor Authentication Bypass
Source: CVE Program / CVE List V5
Vulnerability Description
MISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token counter. The HOTP verification logic compared the submitted token against a counter value that was cached in the user's session at the time the password was entered, rather than against the authoritative counter stored in the database. Because the session-cached counter is not updated after a token is successfully consumed, an attacker who holds a valid session (password already submitted) can reuse a previously burned HOTP token. The stale cached counter still matches the replayed token, granting a second successful authentication and effectively rewinding the counter state. Preconditions: - The target user has HOTP (paper token) second-factor authentication enabled. - The attacker possesses a valid session in which the password step has already been completed (the OTP step is pending). - The attacker has access to at least one HOTP token value (e.g., a paper token list). Security impact: - Bypass of the second authentication factor, allowing unauthorized access to a user's MISP account. - Corruption of the HOTP counter state, potentially invalidating subsequent legitimate tokens or enabling further replays. Affected versions: <2.5.48.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用共享资源的并发执行不恰当同步问题(竞争条件)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MISP MISP 0 ~ 2.5.48 cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-103651

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-103651

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-103651 (1)

Same Patch Batch · MISP · 2026-10-01 · 6 CVEs total

CVE-2026-103655 9.3 CRITICAL MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period
CVE-2026-103659 7.1 HIGH MISP: Object Distribution ACL Bypass via Event Flattening Exposes Organisation-Only Attrib
CVE-2026-103858 5.3 MEDIUM MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussio
CVE-2026-103662 5.1 MEDIUM MISP Reflected XSS in Taxonomy Tag Confirmation Forms
CVE-2026-103664 4.8 MEDIUM MISP Reflected Cross-Site Scripting via Unsanitized Analyst Data Seed Parameter

IV. Related Vulnerabilities

V. Comments for CVE-2026-103651

No comments yet


Leave a comment