目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-85237— 邮箱OTP验证缺少限流导致暴力破解认证

一分钟漏洞结论

影响对象
misp misp
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

MISP 基于电子邮件的一次性密码(OTP)认证流程中存在一个漏洞,允许攻击者进行不限次数的 OTP 验证尝试。 在验证提交的 OTP 值时, 端点未应用防暴力破解机制。一旦攻击者进入 OTP 验证阶段(例如在成功提供用户的主认证凭据之后),他们可以在同一个 OTP 仍然有效期间反复提交候选 OTP 值。这显著提高了猜解 OTP 的可能性,从而可能绕过第二认证因子,最终导致对受影响用户账户的未授权访问。 该问题因 OTP 与用户关联而非与单个待处理登录会话关联而进一步恶化,使得多个并发会话能够针对同一个有效 OTP

CVSS 8.6 · High

影响版本矩阵 1

厂商产品 版本范围状态
misp misp ≤ 2.5.45 affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-85237 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Missing Rate Limiting in Email OTP Verification Allows Brute-Force Authentication Bypass
来源: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint did not apply brute-force protection when validating submitted OTP values. An attacker who had reached the OTP verification stage, for example after successfully providing a user's primary authentication credentials, could repeatedly submit candidate OTP values while the same OTP remained valid. This significantly increased the feasibility of guessing the OTP and bypassing the additional authentication factor, potentially resulting in unauthorized access to the affected user's account. The issue was exacerbated by the fact that the OTP is associated with the user rather than with an individual pending login session, allowing multiple concurrent sessions to attempt guesses against the same valid OTP. The patch integrates the existing MISP brute-force protection mechanism into the email OTP flow. Failed OTP attempts are now counted against the user, further attempts are rejected once the configured threshold is reached, and the active OTP is invalidated when the attempt budget is exhausted. Blocklisted users are also prevented from requesting the generation of a fresh OTP. In addition, OTP comparison now uses hash_equals() and validates that the submitted value is a string.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
过多认证尝试的限制不恰当
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
misp misp 0 ~ 2.5.45 -

二、漏洞 CVE-2026-85237 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-85237 的情报信息

登录查看更多情报信息。

CVE-2026-85237 补丁与修复 (1)

同批安全公告 · misp · 2026-09-03 · 共 9 条

CVE-2026-85216 9.5 CRITICAL MISP 空/无效凭据 LDAP 认证绕过漏洞
CVE-2026-85236 8.8 HIGH MISP cullEmptyEvents CSRF导致GET请求不可逆删除事件漏洞
CVE-2026-85221 7.6 HIGH MISP默认禁用TLS验证致中间人攻击
CVE-2026-85238 7.6 HIGH MISP CustomAuth 认证会话固定导致的劫持漏洞
CVE-2026-85239 7.1 HIGH MISP 事件模板定义校验绕过致服务中断
CVE-2026-85227 6.1 MEDIUM MISP 反射型跨站脚本漏洞
CVE-2026-85226 5.3 MEDIUM MISP OnDemand 相关引擎访问控制缺失漏洞
CVE-2026-85230 5.3 MEDIUM MISP Dashboard 按钮部件 JavaScript 注入漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-85237

暂无评论


发表评论