Impact
The vulnerability lies in MISP’s two‑factor authentication enforcement logic. On instances configured with Security.otp_required, the check that redirects unauthenticated users to the TOTP setup page is only applied to standard browser requests. Non‑browser request shapes—including AJAX/XHR calls, REST API requests, .json URLs, and automation actions—do not trigger the redirect, so the guard is bypassed. An authenticated user who has not enrolled in TOTP can thus issue any non‑browser request and retain full access, nullifying the intended two‑factor protection. This is a standard authentication bypass flaw (CWE‑287) combined with missing required authentication (CWE‑306).
Affected Systems
Affected systems are installations of the MISP platform, version 2.5.47 and earlier, which had the otp_required flag enabled. The fix was implemented in commits 8deb0619e and 6b527ba6e and is included from MISP 2.5.48 onward.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact, though the EPSS score is unavailable and the vulnerability is not listed in KEV. An attacker needs to be authenticated and authorized to make non‑browser requests, which is a realistic scenario for internal users or compromised scripts. Effective exploitation can occur without special privileges beyond those normally granted to legitimate API or automation users. Upgrading to the fixed release mitigates the flaw instantly.
OpenCVE Enrichment