Description
The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthenticate and LinOTPAuthenticate replace CakePHP's FormAuthenticate class but fail to replicate its _checkFields() input validation guard. As a result, the email and password fields extracted from the login request are passed to downstream authentication logic without verifying that they are non-empty strings.

In the LDAP authenticator, an empty or null password is forwarded to ldap_bind(). Per RFC 4513 section 5.1.2, a bind request with a valid DN and an empty password constitutes an unauthenticated bind, which many LDAP directory servers accept as successful. An attacker who knows any valid user email address in the directory can therefore authenticate as that user without possessing a password. Additionally, non-string values (null, false, arrays) are either coerced to empty strings by ldap_bind(), raise TypeErrors, or are misinterpreted as find conditions in _findUser(), all of which can lead to unintended authentication outcomes.

In the LinOTP authenticator, the same missing guard allows non-string credentials to be concatenated into the LinOTP verification request, and in the mixed-authentication branch an empty password is accepted against a stored hash of the empty string.

A secondary issue in the LDAP authenticator is that newly created user accounts (auto-provisioned on first LDAP login) were assigned an empty password. Because the save path skips validation, the empty string is hashed and stored. If the user later ceases to be found in LDAP and the mixed-authentication fallback is used, the stored hash of the empty string verifies against an empty password, again permitting unauthenticated access.

The vulnerability requires that the affected plugin (LdapAuth or LinOTPAuth) is enabled on the MISP instance and that the attacker knows at least one valid email address registered in the directory or MISP user store. No prior authentication is required. Successful exploitation grants the attacker the full privileges of the impersonated user, which may include administrative access to threat intelligence data.


Version affected: ≤2.5.45
Published: 2026-09-14
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Apply Patch
AI Analysis

Impact

The vulnerability stems from missing input validation in MISP’s LdapAuth and LinOTPAuth plugins. Because the email and password fields are passed directly to LDAP and LinOTP authentication logic without checking that they are non‑empty strings, an attacker can send to an unauthenticated LDAP bind or a verification against a stored hash of the empty string, allowing the attacker to log in as any known user without a password. The flaw could also be mixed‑authentication branch, further broadening the attack surface. The overall effect is privileged impersonation, potentially granting administrative access to threat‑intelligence data. The weakness falls under CWE‑20 (Improper Input Validation) and CWE‑287 (Improper Authentication).

Affected Systems

This issue affects MISP installations that have either LdapAuth or LinOTPAuth enabled and are running version 2.5.45 or earlier. The plugins replace CakePHP’s FormAuthenticate class but fail to enforce its input checks. The flaw only manifests when an attacker can supply a valid email address in the target directory or MISP user store; no prior authentication is required.

Risk and Exploitability

The CVSS score of 9.3 while the EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through the web application's login interface (HTTP/HTTPS), and the attacker does not need any existing credentials beyond a known email address. If exploited, the adversary would receive the full privileges of the impersonated user, which can range from read access to sensitive intelligence to full administrative control. The absence of a public exploit does not diminish the risk, as the conditions for bypass are solely related to input validation.

Generated by OpenCVE AI on September 15, 2026 at 13:53 UTC.

Remediation

Vendor Solution

The fix adds explicit type and emptiness validation for the email and password fields in both LdapAuthenticate and LinOTPAuthenticate before any authentication logic is invoked. Non-string or empty credentials are rejected with a logged error and a false return. Additionally, the LDAP authenticator now assigns a cryptographically random password to auto-provisioned user accounts instead of an empty string, preventing the stored hash of '' from being verifiable in the mixed-authentication fallback path. The LinOTP authenticator also rejects an empty password specifically in the mixed-authentication branch where the password is checked against the local database.


OpenCVE Recommended Actions

  • Apply the official MISP patch referenced in commit 0ee058548, which adds explicit type and emptiness checks for email and password fields and assigns a random password to auto‑provisioned accounts.
  • Update MISP to a version newer than 2.5.45 (or apply the patch to the existing installation) to ensure that empty or non‑string credentials are rejected before any authentication logic is invoked.
  • Reconfigure or audit the LDAP server to disallow unauthenticated binds, and confirm that no user account in the local MISP store has a stored hash of an empty string.

Generated by OpenCVE AI on September 15, 2026 at 13:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Misp
Misp misp
Vendors & Products Misp
Misp misp

Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthenticate and LinOTPAuthenticate replace CakePHP's FormAuthenticate class but fail to replicate its _checkFields() input validation guard. As a result, the email and password fields extracted from the login request are passed to downstream authentication logic without verifying that they are non-empty strings. In the LDAP authenticator, an empty or null password is forwarded to ldap_bind(). Per RFC 4513 section 5.1.2, a bind request with a valid DN and an empty password constitutes an unauthenticated bind, which many LDAP directory servers accept as successful. An attacker who knows any valid user email address in the directory can therefore authenticate as that user without possessing a password. Additionally, non-string values (null, false, arrays) are either coerced to empty strings by ldap_bind(), raise TypeErrors, or are misinterpreted as find conditions in _findUser(), all of which can lead to unintended authentication outcomes. In the LinOTP authenticator, the same missing guard allows non-string credentials to be concatenated into the LinOTP verification request, and in the mixed-authentication branch an empty password is accepted against a stored hash of the empty string. A secondary issue in the LDAP authenticator is that newly created user accounts (auto-provisioned on first LDAP login) were assigned an empty password. Because the save path skips validation, the empty string is hashed and stored. If the user later ceases to be found in LDAP and the mixed-authentication fallback is used, the stored hash of the empty string verifies against an empty password, again permitting unauthenticated access. The vulnerability requires that the affected plugin (LdapAuth or LinOTPAuth) is enabled on the MISP instance and that the attacker knows at least one valid email address registered in the directory or MISP user store. No prior authentication is required. Successful exploitation grants the attacker the full privileges of the impersonated user, which may include administrative access to threat intelligence data. Version affected: ≤2.5.45
Title MISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String Credentials
Weaknesses CWE-20
CWE-287
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-09-14T13:55:49.225Z

Reserved: 2026-09-14T13:22:04.165Z

Link: CVE-2026-90961

cve-icon Vulnrichment

Updated: 2026-09-14T13:55:37.668Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T14:17:21.270

Modified: 2026-09-16T13:42:47.997

Link: CVE-2026-90961

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:00:11Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-287

    Improper Authentication