Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107180— MISP: Forced TOTP Enrolment Bypassed via Non-Browser Request Types on otp_required Instances

Quick assessment

Affected
MISP MISP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在配置为要求进行 TOTP 注册的安全策略(Security.otp_required)的 MISP 实例中,强制性的双重身份认证设置仅对标准浏览器请求生效。已通过身份验证但尚未完成 TOTP 注册的用户,可以通过发起任何非浏览器类型的请求(包括 AJAX/XHR 调用、REST API 请求、.json 格式 URL、restSearch 查询或自动化操作)绕过该强制设置。由于这些机器可读的请求形式无法跟随浏览器路径所使用的重定向指令(该重定向会将用户引导至 TOTP 注册页面),因此访问控制守卫(guard)直

CVSS 7.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107180

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MISP: Forced TOTP Enrolment Bypassed via Non-Browser Request Types on otp_required Instances
Source: CVE Program / CVE List V5
Vulnerability Description
On MISP instances configured to require TOTP enrolment (Security.otp_required), the enforcement of the mandatory two-factor authentication setup applied only to standard browser requests. An authenticated user who had not yet enrolled in TOTP could bypass the forced setup by issuing any non-browser request type, including AJAX/XHR calls, REST API requests, .json format URLs, restSearch queries, or automation actions. Because these machine-readable request shapes cannot follow the redirect that the browser path uses to send the user to the TOTP enrolment page, the guard simply skipped the check and the user retained full access to the instance without completing the required second-factor setup. The initial fix (commit 8deb0619e) added a guard specifically for AJAX requests. A follow-up fix (commit 6b527ba6e) broadened the guard to cover every non-browser request shape, while preserving the exemption for identities authenticated via API key (logged_by_authkey flag). Impact: an authenticated user on an otp_required instance can operate with full access indefinitely without enrolling in TOTP, nullifying the instance-level two-factor authentication policy. Affected version: <2.5.48
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MISP MISP 0 ~ 2.5.48 cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-107180

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107180

请登录查看更多情报信息。

Other References for CVE-2026-107180 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-107180

No comments yet


Leave a comment