Description
MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit adversaries targeting MicroRealEstate deployments to brute-force One-Time Passwords (OTP) to log in as any user. This issue affects MicroRealEstate: through 1.0.0-alpha3.
Published: 2026-07-07
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

MicroRealEstate fails to manage token state, allowing attackers to bypass authentication by brute‑forcing One‑Time Passwords (OTP). The flaw constitutes an authentication bypass (CWE‑288) that permits an attacker to log in as any user without valid credentials. The description confirms that an attacker can become any user; it is inferred that this would grant the attacker all privileges associated with that user account, effectively enabling unauthorized access beyond the intended user scope.

Affected Systems

MicroRealEstate software versions up to and including 1.0.0‑alpha3 are affected. All deployments of the product are vulnerable unless a newer release that implements proper token state management is in use.

Risk and Exploitability

The CVSS score of 8.8 classifies this issue as high severity; an EPSS score of < 1% indicates a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Remote attackers can exploit the weakness by targeting the web interface or API endpoint that verifies OTPs, and because no token state is checked they can iteratively guess or brute‑force OTP values to gain authenticated sessions as any user. The likely attack vector is inferred from the description, which mentions bypassing authentication via OTP.

Generated by OpenCVE AI on July 26, 2026 at 19:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MicroRealEstate to a version newer than 1.0.0‑alpha3 that includes proper token state management and OTP validation
  • Implement rate limiting or CAPTCHA on the OTP submission endpoint to impede brute‑force attempts
  • Monitor authentication logs for repeated OTP failures and enforce IP blocking or alerting when thresholds are exceeded

Generated by OpenCVE AI on July 26, 2026 at 19:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title MicroRealEstate Authentication Bypass via OTP Brute-Force

Fri, 24 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute-Force in MicroRealEstate

Tue, 21 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute-Force in MicroRealEstate

Fri, 17 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute‑Force in MicroRealEstate

Wed, 15 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute‑Force in MicroRealEstate

Tue, 14 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute-Force in MicroRealEstate

Mon, 13 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute-Force in MicroRealEstate

Sun, 12 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute-Force in MicroRealEstate

Sat, 11 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute-Force in MicroRealEstate

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Microrealestate
Microrealestate microrealestate
Vendors & Products Microrealestate
Microrealestate microrealestate

Fri, 10 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute-Force in MicroRealEstate

Thu, 09 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute-Force in MicroRealEstate

Wed, 08 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute‑Force Vulnerability in MicroRealEstate

Tue, 07 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute‑Force Vulnerability in MicroRealEstate

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit adversaries targeting MicroRealEstate deployments to brute-force One-Time Passwords (OTP) to log in as any user. This issue affects MicroRealEstate: through 1.0.0-alpha3.
Weaknesses CWE-288
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Microrealestate Microrealestate
cve-icon MITRE

Status: PUBLISHED

Assigner: TML

Published:

Updated: 2026-07-07T13:35:02.868Z

Reserved: 2026-06-26T00:40:34.057Z

Link: CVE-2026-57867

cve-icon Vulnrichment

Updated: 2026-07-07T13:34:59.649Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:45:03Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel