Description
MISP contains a race condition in the email-based one-time password (OTP) login flow. When two HTTP requests carrying the same valid OTP are submitted concurrently, both can successfully authenticate and establish a session. The root cause is that the OTP value is read from the shared store, validated, and then deleted in separate non-atomic steps, allowing a second in-flight request to read the same value before the first request's deletion takes effect.

Preconditions:

- The target MISP instance has email OTP login enabled.

- The attacker possesses a valid, unexpired OTP (e.g., via email interception or social engineering).

- The attacker can issue two HTTP POST requests in close temporal proximity.

Impact:

- The one-time-use guarantee of the OTP is violated; a single code can yield two authenticated sessions.

- This weakens the authentication control and may facilitate unauthorized access if the OTP is shared or intercepted.

Affected versions: <2.5.48
Published: 2026-10-07
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

The fix makes OTP consumption atomic by moving the deletion of the OTP from the shared store into the validation condition itself. The return value of the delete operation (1 if the key was actually removed, 0 otherwise) is now part of the success check, so only the request that successfully removes the OTP from the store is permitted to proceed with login. A session-state cleanup call was also added to remove the OTP user reference from the session.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
Description MISP contains a race condition in the email-based one-time password (OTP) login flow. When two HTTP requests carrying the same valid OTP are submitted concurrently, both can successfully authenticate and establish a session. The root cause is that the OTP value is read from the shared store, validated, and then deleted in separate non-atomic steps, allowing a second in-flight request to read the same value before the first request's deletion takes effect. Preconditions: - The target MISP instance has email OTP login enabled. - The attacker possesses a valid, unexpired OTP (e.g., via email interception or social engineering). - The attacker can issue two HTTP POST requests in close temporal proximity. Impact: - The one-time-use guarantee of the OTP is violated; a single code can yield two authenticated sessions. - This weakens the authentication control and may facilitate unauthorized access if the OTP is shared or intercepted. Affected versions: <2.5.48
Title MISP Email OTP Race Condition Allows One-Time Password to Be Consumed by Multiple Concurrent Requests
First Time appeared Misp
Misp misp
Weaknesses CWE-362
CWE-367
CPEs cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
Vendors & Products Misp
Misp misp
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-10-07T15:36:49.564Z

Reserved: 2026-10-07T15:36:46.122Z

Link: CVE-2026-107276

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-07T16:17:47.213

Modified: 2026-10-07T16:17:47.340

Link: CVE-2026-107276

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition