Description
MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window.

The issue exists in the user login flow where a TOTP code is verified as a second authentication factor. Because the system did not record whether a given TOTP period had already been consumed, the same code remained valid for its entire time window (typically 30 seconds). An attacker who captures a legitimate code during a user's login could replay it to authenticate a second session as that user.

Preconditions:

- The target user has TOTP-based two-factor authentication enabled.

- The attacker is in a position to observe or intercept the TOTP code during a legitimate login (e.g., network-level interception, shoulder surfing, or a compromised client).

- The replay must occur within the TOTP validity period.

Security impact:

- Unauthorized account access by replaying a captured one-time code.

- Potential compromise of threat-intelligence data and administrative functions accessible to the targeted user.

Affected versions: <v2.5.48.
Published: 2026-10-01
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Unauthorized account access via TOTP replay
Action: Immediate Patch
AI Analysis

Impact

MISP's two‑factor authentication process was found to allow the same TOTP code to be used more than once within its time window. The vulnerability is caused by the absence of a record of a consumed TOTP period, so a code remains valid for the entire 30‑second window. An attacker who captures a legitimate code during a user's login can replay it, enabling unauthorized access to the victim’s account and the data or administrative functions protected by that account.

Affected Systems

The flaw affects all MISP installations that use two‑factor authentication and run a version older than 2.5.48. The affected product is the MISP platform itself, and the vulnerability is present in any deployed instance before the vendor released the patch that introduces a single‑use enforcement mechanism.

Risk and Exploitability

The criticality of the vulnerability is reflected in a 9.3 CVSS score, indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the weakness by observing or intercepting a TOTP code during a legitimate authentication – either through network‑level eavesdropping, shoulder surfing, or a compromised client – and then replaying that code before the 30‑second validity period expires. Because the vulnerability requires the target user to have two‑factor enabled, the attack surface is limited to those accounts, but once an attacker succeeds, they gain full access to two‑factor authenticated sessions.

Generated by OpenCVE AI on October 1, 2026 at 09:36 UTC.

Remediation

Vendor Solution

The fix introduces a single-use enforcement mechanism for TOTP codes. Upon successful verification, the system records the TOTP period step in a Redis key scoped to the user and step number, using a SET-NX (set-if-not-exists) operation with a TTL of three times the TOTP period. Any subsequent attempt to authenticate with a code from the same period will fail the SET-NX check and be rejected, effectively making each TOTP code single-use within its validity window.


OpenCVE Recommended Actions

  • Apply the MISP update to version 2.5.48 or later to enable single‑use enforcement of TOTP codes.
  • If immediate update is not possible, temporarily disable two‑factor authentication for the affected user accounts until the patch is applied.
  • After updating, test that a captured TOTP cannot be reused and monitor authentication logs for repeated TOTP attempts.

Generated by OpenCVE AI on October 1, 2026 at 09:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
Description MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window. The issue exists in the user login flow where a TOTP code is verified as a second authentication factor. Because the system did not record whether a given TOTP period had already been consumed, the same code remained valid for its entire time window (typically 30 seconds). An attacker who captures a legitimate code during a user's login could replay it to authenticate a second session as that user. Preconditions: - The target user has TOTP-based two-factor authentication enabled. - The attacker is in a position to observe or intercept the TOTP code during a legitimate login (e.g., network-level interception, shoulder surfing, or a compromised client). - The replay must occur within the TOTP validity period. Security impact: - Unauthorized account access by replaying a captured one-time code. - Potential compromise of threat-intelligence data and administrative functions accessible to the targeted user. Affected versions: <v2.5.48.
Title MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period
First Time appeared Misp
Misp misp
Weaknesses CWE-294
CPEs cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
Vendors & Products Misp
Misp misp
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-10-01T15:25:55.269Z

Reserved: 2026-10-01T08:08:52.909Z

Link: CVE-2026-103655

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T09:17:07.867

Modified: 2026-10-01T16:17:37.487

Link: CVE-2026-103655

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T09:45:04Z

Weaknesses
  • CWE-294

    Authentication Bypass by Capture-replay