CVE-2026-103655
Deferred Deferred - Pending Action

Reused TOTP Code in MISP Authentication

Vulnerability report for CVE-2026-103655, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: CIRCL

Description

MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window. The issue exists in the user login flow where a TOTP code is verified as a second authentication factor. Because the system did not record whether a given TOTP period had already been consumed, the same code remained valid for its entire time window (typically 30 seconds). An attacker who captures a legitimate code during a user's login could replay it to authenticate a second session as that user. Preconditions: - The target user has TOTP-based two-factor authentication enabled. - The attacker is in a position to observe or intercept the TOTP code during a legitimate login (e.g., network-level interception, shoulder surfing, or a compromised client). - The replay must occur within the TOTP validity period. Security impact: - Unauthorized account access by replaying a captured one-time code. - Potential compromise of threat-intelligence data and administrative functions accessible to the targeted user. Affected versions: <v2.5.48.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
misp misp to 2.5.48 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-294 A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MISP has a flaw in its two-factor authentication (TOTP) system where a valid one-time code can be used more than once within its 30-second validity window. The system did not track if a code was already used, allowing attackers who capture a legitimate code during login to replay it and gain unauthorized access.

Detection Guidance

To detect this vulnerability, monitor for multiple successful logins using the same TOTP code within the validity window. Check MISP logs for repeated authentication attempts with identical codes. Review Redis storage for TOTP usage tracking to ensure codes are marked as consumed after first use.

Impact Analysis

If you use MISP with TOTP enabled, an attacker could intercept your one-time code and reuse it to log in as you. This could lead to unauthorized access to your account, exposure of threat-intelligence data, or misuse of administrative functions if you have elevated privileges.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements under GDPR and HIPAA. Compromised accounts may expose personal or health information, resulting in non-compliance with data protection regulations.

Mitigation Strategies

Upgrade MISP to version 2.5.48 or later to address the TOTP replay vulnerability. Review authentication logs for suspicious repeated login attempts within the TOTP validity window.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103655. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart