CVE-2026-107276 — MISP contains a race condition in the email-based one-time password (OTP) login flow.
Description
MISP contains a race condition in the email-based one-time password (OTP) login flow. When two HTTP requests carrying the same valid OTP are submitted concurrently, both can successfully authenticate and establish a session. The root cause is that the OTP value is read from the shared store, validated, and then deleted in separate non-atomic steps, allowing a second in-flight request to read the same value before the first request's deletion takes effect. Preconditions: - The target MISP instance has email OTP login enabled. - The attacker possesses a valid, unexpired OTP (e.g., via email interception or social engineering). - The attacker can issue two HTTP POST requests in close temporal proximity. Impact: - The one-time-use guarantee of the OTP is violated; a single code can yield two authenticated sessions. - This weakens the authentication control and may facilitate unauthorized access if the OTP is shared or intercepted. Affected versions: <2.5.48
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
High
Attack Complexity
AT
None
Attack Requirements
PR
None
Privileges Required
UI
None
User Interaction
VC
None
Confidentiality (Vulnerable System)
VI
Low
Integrity (Vulnerable System)
VA
None
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
Low
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
Related threats
same CWE or vendorCVE-2026-84271 — IBM Guardium Data Protection 12.2 is vulnerable to a signature verification bypass in the patch installer.
CVE-2026-84271 · 2h ago
PraisonAI: DNS rebinding bypass in `web_crawl` SSRF protection allows internal response disclosure
CVE-2026-61430 · 6h ago
CVE-2026-42698 — Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Themeum Tutor LMS tutor allows Leverag…
CVE-2026-42698 · 8h ago
CVE-2026-94584 — A race condition and thread-safety vulnerability exists in the web management daemon of Brocade Fabric OS versions before 10.0.1.
CVE-2026-94584 · 18h ago
CVE-2026-94583 — A race condition vulnerability exists in the request processing logic of the REST management interface on Brocade Fabric OS versions before 10.0.1.
CVE-2026-94583 · 19h ago
PraisonAI: Crawl4AI/Chromium backend is also affected by the `web_crawl` SSRF validation bypass
CVE-2026-61429 · 1d ago