Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-95754— MISP: Disabled-user check ineffective in pre-authentication TOTP login branch

Quick assessment

Affected
MISP MISP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentication) verification branch did not include the User.disabled column in its SELECT fields list. The query selected only User.password, User.to

CVSS 6.9 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
MISP MISP < 2.5.47 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-95754

Vulnerability Information

Shenlong is analyzing...


Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MISP: Disabled-user check ineffective in pre-authentication TOTP login branch
Source: CVE Program / CVE List V5
Vulnerability Description
In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentication) verification branch did not include the User.disabled column in its SELECT fields list. The query selected only User.password, User.totp, and User.hotp_counter. When the TOTP branch subsequently accessed $unauth_user['User']['disabled'], the key was absent from the result set, producing a PHP 'Undefined array key' warning and causing the expression to evaluate as null (falsy). As a result, the disabled-user guard in the TOTP branch was effectively a no-op: a disabled, TOTP-enrolled user could proceed to the TOTP verification step rather than being rejected at that point.  The commit message explicitly states this was 'harmless in practice' because the subsequent identify() call re-validates the user and would still reject a disabled account.  The practical security impact is therefore minimal, limited to a very small information-disclosure difference in the login response (a TOTP prompt is presented instead of an immediate rejection) and a PHP warning in application logs.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MISP MISP 0 ~ 2.5.47 -

II. Public POCs for CVE-2026-95754

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-95754

登录查看更多情报信息。

Patches & Fixes for CVE-2026-95754 (1)

Same Patch Batch · MISP · 2026-09-22 · 19 CVEs total

CVE-2026-95806 7.7 HIGH MISP: PHP phar stream wrapper enables deserialization and code execution via caller-influe
CVE-2026-95658 6.9 MEDIUM MISP CSRF vulnerability in workflow moduleStatelessExecution allows cross-site execution o
CVE-2026-95679 6.9 MEDIUM MISP Unauthenticated Blind SSRF via XML Body Processing
CVE-2026-95667 6.9 MEDIUM MISP Installer Log and FIFO Created World-Readable, Exposing Sensitive Credentials
CVE-2026-95693 5.3 MEDIUM MISP Information Disclosure via Forged Upload Path
CVE-2026-95805 5.3 MEDIUM MISP ACLComponent: Typo in previewEventAttributes ACL key bypasses intended access restric
CVE-2026-95698 5.3 MEDIUM MISP Path Traversal in OrgImgHelper findOrgImage via Crafted Organization Name
CVE-2026-95671 5.3 MEDIUM MISP Collections: Missing Authorization Check for Sharing Group on PUT Request in collecti
CVE-2026-95685 5.3 MEDIUM MISP Missing Authorization on replaceSuggestionInReport Event Report Action
CVE-2026-95674 5.3 MEDIUM MISP EventsController queryEnrichment allows querying unavailable or legacy modules withou
CVE-2026-95683 5.3 MEDIUM MISP Overmind Event View Discloses Report Content Bypassing Report-Level ACL
CVE-2026-95697 5.3 MEDIUM MISP: Insufficient Authorization Allows Sharing Group Editors to Overwrite Organization Me
CVE-2026-95661 5.1 MEDIUM MISP Reflected Cross-Site Scripting in Attribute Histogram via Unescaped URL-Supplied Type
CVE-2026-95665 5.1 MEDIUM MISP Reflected Cross-Site Scripting in Event Export Confirmation Form via Unescaped JSON
CVE-2026-95703 5.1 MEDIUM MISP OrganisationsController File Existence and Image-Type Oracle via Forged Upload tmp_na
CVE-2026-95701 5.1 MEDIUM MISP Path Traversal via Organization Name in Org-Statistics Logo Check
CVE-2026-95659 4.8 MEDIUM MISP Reflected XSS via Unvalidated Object Type in AnalystData Overmind Thread
CVE-2026-95682 4.8 MEDIUM MISP Stored Cross-Site Scripting via Unescaped Organization Name in Admin Email View

IV. Related Vulnerabilities

V. Comments for CVE-2026-95754

No comments yet


Leave a comment