CVE-2026-107180
Deferred Deferred - Pending Action

Authentication Bypass in MISP via Non-Browser Requests

Vulnerability report for CVE-2026-107180, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: CIRCL

Description

On MISP instances configured to require TOTP enrolment (Security.otp_required), the enforcement of the mandatory two-factor authentication setup applied only to standard browser requests. An authenticated user who had not yet enrolled in TOTP could bypass the forced setup by issuing any non-browser request type, including AJAX/XHR calls, REST API requests, .json format URLs, restSearch queries, or automation actions. Because these machine-readable request shapes cannot follow the redirect that the browser path uses to send the user to the TOTP enrolment page, the guard simply skipped the check and the user retained full access to the instance without completing the required second-factor setup. The initial fix (commit 8deb0619e) added a guard specifically for AJAX requests. A follow-up fix (commit 6b527ba6e) broadened the guard to cover every non-browser request shape, while preserving the exemption for identities authenticated via API key (logged_by_authkey flag). Impact: an authenticated user on an otp_required instance can operate with full access indefinitely without enrolling in TOTP, nullifying the instance-level two-factor authentication policy. Affected version: <2.5.48

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
MISP MISP 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects MISP instances where TOTP enrollment is mandatory (Security.otp_required). An authenticated user who had not enrolled in TOTP could bypass the forced setup by making non-browser requests like AJAX, REST API calls, or automation actions. The system failed to enforce TOTP requirements for these request types, allowing full access without completing the second-factor setup.

Detection Guidance

To detect this vulnerability, check MISP logs for requests from authenticated users without TOTP enrollment that bypass the enrollment page. Look for non-browser requests like AJAX/XHR calls, REST API requests, .json format URLs, restSearch queries, or automation actions returning successful responses without enforcing TOTP setup.

Impact Analysis

If you run a MISP instance with TOTP required, an attacker could exploit this to gain full access without setting up TOTP. This undermines the security policy of your instance, allowing unauthorized users to perform actions as if they were fully authenticated. The vulnerability affects all versions before 2.5.48.

Compliance Impact

This vulnerability allows authenticated users to bypass mandatory two-factor authentication (TOTP) on MISP instances where TOTP enrollment is required. This could undermine compliance with data protection regulations like GDPR and HIPAA, which often mandate strong authentication controls for handling sensitive data. Unauthorized access risks exposure of personal or health information, violating confidentiality and integrity requirements.

Mitigation Strategies

Upgrade MISP to version 2.5.48 or later to apply the fixes. Ensure all non-browser requests from unenrolled users are blocked by verifying the enforcement of TOTP setup across all request types. Exempt API key-based authentication from this requirement.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107180. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart