Impact
The vulnerability stems from missing input validation in MISP’s LdapAuth and LinOTPAuth plugins. Because the email and password fields are passed directly to LDAP and LinOTP authentication logic without checking that they are non‑empty strings, an attacker can send to an unauthenticated LDAP bind or a verification against a stored hash of the empty string, allowing the attacker to log in as any known user without a password. The flaw could also be mixed‑authentication branch, further broadening the attack surface. The overall effect is privileged impersonation, potentially granting administrative access to threat‑intelligence data. The weakness falls under CWE‑20 (Improper Input Validation) and CWE‑287 (Improper Authentication).
Affected Systems
This issue affects MISP installations that have either LdapAuth or LinOTPAuth enabled and are running version 2.5.45 or earlier. The plugins replace CakePHP’s FormAuthenticate class but fail to enforce its input checks. The flaw only manifests when an attacker can supply a valid email address in the target directory or MISP user store; no prior authentication is required.
Risk and Exploitability
The CVSS score of 9.3 while the EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through the web application's login interface (HTTP/HTTPS), and the attacker does not need any existing credentials beyond a known email address. If exploited, the adversary would receive the full privileges of the impersonated user, which can range from read access to sensitive intelligence to full administrative control. The absence of a public exploit does not diminish the risk, as the conditions for bypass are solely related to input validation.
OpenCVE Enrichment