Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-92003— MISP Unthrottled Authentication Failure Log Writes Enable Resource Exhaustion

Quick assessment

Affected
MISP MISP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

受影响版本的 MISP 未能一致地应用现有的认证失败日志记录限流机制。 两个 API 认证失败的分支直接写入了 Log 模型: 未提供认证密钥的 API 请求; 提供了长度不正确的 API 密钥的请求。 与其他认证失败情形不同,这些代码路径绕过了 函数,因此每个请求都可能创建一条新的持久化 日志条目。 受影响版本:≤ 2.5.45

CVSS 6.9 · Medium

Possible ATT&CK Techniques 1 AI

T1552.001 · Credentials In Files
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92003

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MISP Unthrottled Authentication Failure Log Writes Enable Resource Exhaustion
Source: CVE Program / CVE List V5
Vulnerability Description
Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model:  - API requests with no authentication key;  - requests supplying an API key with an incorrect length Unlike other authentication failures, these paths bypassed _shouldLog(), so every request could create another durable auth_fail entry. Version affected: ≤2.5.45
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MISP MISP 0 ~ 2.5.46 -

II. Public POCs for CVE-2026-92003

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92003

登录查看更多情报信息。

Patches & Fixes for CVE-2026-92003 (1)

Same Patch Batch · MISP · 2026-09-15 · 8 CVEs total

CVE-2026-91825 7.1 HIGH MISP: Missing Authorization Check for Event Sharing Group When Distribution Field Is Omitt
CVE-2026-91846 7.1 HIGH MISP Collection Element Add Missing Authorization on Referenced Object UUID
CVE-2026-91819 6.9 MEDIUM MISP: HTTP Method Override Bypasses CSRF and Form Validation in BetterSecurityComponent
CVE-2026-91851 5.3 MEDIUM MISP Dashboard Template ACL Bypass Due to VARCHAR-to-Integer Type Coercion in Permission F
CVE-2026-91857 5.3 MEDIUM MISP: State-changing actions accessible via GET request enabling CSRF
CVE-2026-91859 5.3 MEDIUM MISP Access Log Entry Overwritten by Error Controller's Second beforeFilter Pass
CVE-2026-92002 5.1 MEDIUM MISP: Authentication failure logging suppressed during Redis unavailability

IV. Related Vulnerabilities

V. Comments for CVE-2026-92003

No comments yet


Leave a comment