CVE-2026-103651
Deferred Deferred - Pending Action

HOTP Replay Vulnerability in MISP

Vulnerability report for CVE-2026-103651, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: CIRCL

Description

MISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token counter. The HOTP verification logic compared the submitted token against a counter value that was cached in the user's session at the time the password was entered, rather than against the authoritative counter stored in the database. Because the session-cached counter is not updated after a token is successfully consumed, an attacker who holds a valid session (password already submitted) can reuse a previously burned HOTP token. The stale cached counter still matches the replayed token, granting a second successful authentication and effectively rewinding the counter state. Preconditions: - The target user has HOTP (paper token) second-factor authentication enabled. - The attacker possesses a valid session in which the password step has already been completed (the OTP step is pending). - The attacker has access to at least one HOTP token value (e.g., a paper token list). Security impact: - Bypass of the second authentication factor, allowing unauthorized access to a user's MISP account. - Corruption of the HOTP counter state, potentially invalidating subsequent legitimate tokens or enabling further replays. Affected versions: <2.5.48.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
misp misp to 2.5.48 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-362 The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in MISP allows replay of a used HOTP (paper) token due to incorrect counter validation. The system cached the counter in the user's session instead of checking the authoritative counter in the database. This lets an attacker with an active session reuse a burned token, bypassing second-factor authentication and potentially rewinding the counter state.

Detection Guidance

To detect this vulnerability, check if your MISP instance is running a version prior to 2.5.48. Verify HOTP token handling by inspecting session-cached counter values against database-stored counters. Look for repeated token usage or counter rewinding in logs.

Impact Analysis

If you use MISP with HOTP authentication, an attacker with a valid session could reuse your burned tokens to gain unauthorized access to your account. This bypasses the second authentication factor, allowing them to impersonate you or manipulate the system's HOTP counter.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. It undermines multi-factor authentication, a key control for protecting personal or health information.

Mitigation Strategies

Immediately upgrade MISP to version 2.5.48 or later. Disable HOTP authentication if possible until patched. Review session logs for suspicious token reuse or counter inconsistencies. Ensure Redis locks are properly implemented during token verification.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103651. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart