CVE-2026-107276 PUBLISHED

MISP Email OTP Race Condition Allows One-Time Password to Be Consumed by Multiple Concurrent Requests

Assigner: CIRCL
Reserved: 07.10.2026 Published: 07.10.2026 Updated: 07.10.2026

MISP contains a race condition in the email-based one-time password (OTP) login flow. When two HTTP requests carrying the same valid OTP are submitted concurrently, both can successfully authenticate and establish a session. The root cause is that the OTP value is read from the shared store, validated, and then deleted in separate non-atomic steps, allowing a second in-flight request to read the same value before the first request's deletion takes effect.

Preconditions:

  • The target MISP instance has email OTP login enabled.

  • The attacker possesses a valid, unexpired OTP (e.g., via email interception or social engineering).

  • The attacker can issue two HTTP POST requests in close temporal proximity.

Impact:

  • The one-time-use guarantee of the OTP is violated; a single code can yield two authenticated sessions.

  • This weakens the authentication control and may facilitate unauthorized access if the OTP is shared or intercepted.

Affected versions: <2.5.48

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
CVSS Score: 6.3

Product Status

Vendor MISP
Product MISP
Versions
  • affected from 0 to 2.5.48 (excl.)

Solutions

The fix makes OTP consumption atomic by moving the deletion of the OTP from the shared store into the validation condition itself. The return value of the delete operation (1 if the key was actually removed, 0 otherwise) is now part of the success check, so only the request that successfully removes the OTP from the store is permitted to proceed with login. A session-state cleanup call was also added to remove the OTP user reference from the session.

Credits

  • iglocska remediation developer
  • Claude Opus 5.5 (1M context) remediation developer

References

Problem Types

  • CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition) CWE
  • CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition CWE

Impacts

  • CAPEC-111 Race Condition