MISP 基于电子邮件的一次性密码(OTP)认证流程中存在一个漏洞,允许攻击者进行不限次数的 OTP 验证尝试。 在验证提交的 OTP 值时, 端点未应用防暴力破解机制。一旦攻击者进入 OTP 验证阶段(例如在成功提供用户的主认证凭据之后),他们可以在同一个 OTP 仍然有效期间反复提交候选 OTP 值。这显著提高了猜解 OTP 的可能性,从而可能绕过第二认证因子,最终导致对受影响用户账户的未授权访问。 该问题因 OTP 与用户关联而非与单个待处理登录会话关联而进一步恶化,使得多个并发会话能够针对同一个有效 OTP
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85216 | 9.5 CRITICAL | MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials |
| CVE-2026-85236 | 8.8 HIGH | MISP cullEmptyEvents CSRF Allows Irreversible Deletion of Events via GET Request |
| CVE-2026-85221 | 7.6 HIGH | MISP CurlClient TLS Peer Verification Disabled by Default Enables Man-in-the-Middle Attack |
| CVE-2026-85238 | 7.6 HIGH | Session Fixation in MISP CustomAuth Authentication Allows Session Hijacking |
| CVE-2026-85239 | 7.1 HIGH | MISP Event Template Definition Validation Bypass Allows Persistent Denial of Service |
| CVE-2026-85227 | 6.1 MEDIUM | Reflected Cross-Site Scripting in MISP Event Filtering via taggedAttributes and galaxyAtta |
| CVE-2026-85226 | 5.3 MEDIUM | MISP OnDemand Correlation Engine Missing Access Control Allows Disclosure of Restricted Co |
| CVE-2026-85230 | 5.3 MEDIUM | MISP Dashboard Button Widget Allows Persistent JavaScript URL Injection |
No comments yet