Description
Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid excessive duplicate logs while still recording failed authentication activity.


However, User->setupRedis() returns false when Redis cannot be reached. The vulnerable _shouldLog() logic only returned true when a Redis instance existed and no throttle key was present. Therefore, when Redis was unavailable, the function did not allow the log write at all, effectively silencing authentication-failure logging for the duration of the outage.

Version affected: ≤2.5.45
Published: 2026-09-15
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Audit Trail Suppression
Action: Apply Patch
AI Analysis

Impact

MISP implements throttling of authentication-failure log entries with a Redis key. The code only logs a failure when Redis is reachable and no throttle key is present. If the Redis connection cannot be established, the function silently suppresses every authentication-failure event. This loss of logging (CWE-778) weakens the visibility of authentication failures, undermining the ability to detect brute-force or credential-theft activity.

Affected Systems

Affected versions are all releases of the MISP platform up to and including 2.5.45. The issue resides in the MISP application provided by the vendor MISP: MISP. Administrators using these versions are at risk until the application is upgraded.

Risk and Exploitability

The CVSS score is 5.1, indicating moderate severity. The EPSS score is less than 1%, indicating a low probability; it is not listed in the CISA KEV catalog. Exploitation requires an attacker to disrupt or otherwise make unavailable the Redis service used by MISP for throttling. The effect is suppression of authentication-failure logging, which limits audit visibility but does not provide code execution or compromise of confidentiality. Organizations should consider the moderate risk, particularly if a Redis outage occurs.

Generated by OpenCVE AI on September 17, 2026 at 17:49 UTC.

Remediation

Vendor Solution

The _shouldLog() method now explicitly checks whether the Redis connection is available before attempting to use it. If setupRedis() returns false, the method immediately returns true, causing every authentication-failure event to be logged. This converts the previous fail-closed behavior (silence on dependency failure) into a fail-open behavior for security logging (log everything when the throttle state is unavailable), ensuring that a Redis outage cannot be used to suppress the audit trail of failed authentication attempts.


OpenCVE Recommended Actions

  • Upgrade MISP to a version newer than 2.5.45 where the _shouldLog() change is implemented
  • Configure Redis with high-availability or redundant deployment and monitor its uptime to prevent logging suppression during outages
  • Add a local fallback log for authentication-failure events that writes to the file system when Redis is unavailable, ensuring audit-trail continuity

Generated by OpenCVE AI on September 17, 2026 at 17:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Misp
Misp misp
Vendors & Products Misp
Misp misp

Tue, 15 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid excessive duplicate logs while still recording failed authentication activity. However, User->setupRedis() returns false when Redis cannot be reached. The vulnerable _shouldLog() logic only returned true when a Redis instance existed and no throttle key was present. Therefore, when Redis was unavailable, the function did not allow the log write at all, effectively silencing authentication-failure logging for the duration of the outage. Version affected: ≤2.5.45
Title MISP: Authentication failure logging suppressed during Redis unavailability
Weaknesses CWE-778
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-09-15T12:09:48.540Z

Reserved: 2026-09-15T11:24:19.778Z

Link: CVE-2026-92002

cve-icon Vulnrichment

Updated: 2026-09-15T12:04:29.010Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T12:17:55.557

Modified: 2026-09-16T13:42:49.027

Link: CVE-2026-92002

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:15:13Z

Weaknesses