CVE-2026-107180 Details
Description
On MISP instances configured to require TOTP enrolment (Security.otp_required), the enforcement of the mandatory two-factor authentication setup applied only to standard browser requests. An authenticated user who had not yet enrolled in TOTP could bypass the forced setup by issuing any non-browser request type, including AJAX/XHR calls, REST API requests, .json format URLs, restSearch queries, or automation actions. Because these machine-readable request shapes cannot follow the redirect that the browser path uses to send the user to the TOTP enrolment page, the guard simply skipped the check and the user retained full access to the instance without completing the required second-factor setup. The initial fix (commit 8deb0619e) added a guard specifically for AJAX requests. A follow-up fix (commit 6b527ba6e) broadened the guard to cover every non-browser request shape, while preserving the exemption for identities authenticated via API key (logged_by_authkey flag). Impact: an authenticated user on an otp_required instance can operate with full access indefinitely without enrolling in TOTP, nullifying the instance-level two-factor authentication policy. Affected version: <2.5.48
A vulnerability exists in MISP instances that mandate TOTP enrolment. The requirement for two-factor authentication is enforced only on standard browser requests. As a result, an authenticated user who has not enrolled in TOTP can bypass this requirement by using non-browser request types, such as AJAX, REST API calls, .json format URLs, restSearch queries, or automation actions. These machine-readable request types cannot follow the browser's redirect to the TOTP enrolment page, allowing the user to maintain full access to the instance without completing the necessary two-factor authentication. The vulnerability affects MISP versions prior to 2.5.48.
Users can update to MISP version 2.5.48 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 7, 2026CISA-ADP
Assessed Oct 7, 2026Supplier
Assessed Oct 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/MISP/MISP/commit/6b527ba6e | CIRCL | Source CodeVendor |
| https://github.com/MISP/MISP/commit/8deb0619e | CIRCL | Source CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | CIRCL |
| CWE-306 | Missing Authentication for Critical Function | CIRCL |
Affected Products
| Product | Versions |
|---|---|
| MISP | < 2.5.48 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Oct 7, 2026 | CVE Modified | CISA-ADP |
| Oct 7, 2026 | New CVE Received | CIRCL |
Volerion