Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107276— MISP Email OTP Race Condition Allows One-Time Password to Be Consumed by Multiple Concurrent Requests

Quick assessment

Affected
MISP MISP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MISP 在基于电子邮件的一次性密码(OTP)登录流程中存在竞态条件漏洞。当两个携带相同有效 OTP 的 HTTP 请求并发提交时,两者均能成功完成身份验证并建立会话。根本原因在于,OTP 值的读取、验证和删除操作是分步执行的,且这些步骤并非原子操作,从而导致第二个进行中的请求可能在第一个请求的删除操作生效之前,读取到相同的 OTP 值。 前提条件: 目标 MISP 实例已启用电子邮件 OTP 登录功能。 攻击者拥有有效的、未过期的 OTP(例如,通过邮件拦截或社会工程学手段获取)。 攻击者能够在时间上非常接近地发

CVSS 6.3 · Medium

Possible ATT&CK Techniques 1 AI

T1110.003 · Password Spraying
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107276

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MISP Email OTP Race Condition Allows One-Time Password to Be Consumed by Multiple Concurrent Requests
Source: CVE Program / CVE List V5
Vulnerability Description
MISP contains a race condition in the email-based one-time password (OTP) login flow. When two HTTP requests carrying the same valid OTP are submitted concurrently, both can successfully authenticate and establish a session. The root cause is that the OTP value is read from the shared store, validated, and then deleted in separate non-atomic steps, allowing a second in-flight request to read the same value before the first request's deletion takes effect. Preconditions: - The target MISP instance has email OTP login enabled. - The attacker possesses a valid, unexpired OTP (e.g., via email interception or social engineering). - The attacker can issue two HTTP POST requests in close temporal proximity. Impact: - The one-time-use guarantee of the OTP is violated; a single code can yield two authenticated sessions. - This weakens the authentication control and may facilitate unauthorized access if the OTP is shared or intercepted. Affected versions: <2.5.48
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用共享资源的并发执行不恰当同步问题(竞争条件)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MISP MISP 0 ~ 2.5.48 cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-107276

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107276

请登录查看更多情报信息。

Other References for CVE-2026-107276 (1)

Same Patch Batch · MISP · 2026-10-07 · 4 CVEs total

CVE-2026-107180 7.1 HIGH MISP: Forced TOTP Enrolment Bypassed via Non-Browser Request Types on otp_required Instanc
CVE-2026-107175 5.3 MEDIUM MISP Correlation Engine Fails to Refresh When Event Distribution or Sharing Group Changes
CVE-2026-107278 5.3 MEDIUM MISP Object Sync Drops Objects and Attributes When Description Is Empty

IV. Related Vulnerabilities

V. Comments for CVE-2026-107276

No comments yet


Leave a comment